PT-2021-7019 · Cisco · Cisco Unified Communications Manager+1
Published
2021-11-02
·
Updated
2022-05-03
·
CVE-2022-20789
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) (affected versions not specified)
Description
A vulnerability in the software upgrade process could allow an authenticated, remote attacker to write arbitrary files on the affected system. This issue is due to improper restrictions applied to a system script. An attacker could exploit this by using crafted variables during the execution of a system upgrade, potentially allowing them to overwrite or append arbitrary data to system files using root-level privileges.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Unified Communications Manager
Cisco Unified Communications Manager Session Management Edition