PT-2021-2576 · Cisco · Cisco Unified Communications Manager+1

Mohamed Youssef

·

Published

2021-04-07

·

Updated

2021-04-13

·

CVE-2021-1399

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Unified Communications Manager versions (affected versions not specified) Cisco Unified Communications Manager Session Management Edition versions (affected versions not specified)
Description A vulnerability in the Self Care Portal could allow an authenticated, remote attacker to modify data on an affected system without proper authorization. The issue is due to insufficient validation of user-supplied data to the Self Care Portal. An attacker could exploit this by sending a crafted HTTP request to an affected system, potentially allowing them to modify information without proper authorization.
Recommendations For Cisco Unified Communications Manager, update to a version that includes the fix for this issue. For Cisco Unified Communications Manager Session Management Edition, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the Self Care Portal until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02027
CVE-2021-1399

Affected Products

Cisco Unified Communications Manager
Cisco Unified Communications Manager Session Management Edition