PT-2019-3346 · Cisco · Cisco Unified Contact Center Express

Published

2019-09-04

·

Updated

2020-10-08

·

CVE-2019-12633

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco Unified Contact Center Express (Unified CCX) (affected versions not specified)
Description A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on a targeted system. The issue is due to improper validation of user-supplied input on the affected system. An attacker could exploit this by sending a crafted request to the user of the web application. If the request is processed, the attacker could access the system and perform unauthorized actions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03476
CVE-2019-12633

Affected Products

Cisco Unified Contact Center Express