PT-2021-7019 · Cisco · Cisco Unified Communications Manager+1

Published

2021-11-02

·

Updated

2022-05-03

·

CVE-2022-20789

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) (affected versions not specified)
Description A vulnerability in the software upgrade process could allow an authenticated, remote attacker to write arbitrary files on the affected system. This issue is due to improper restrictions applied to a system script. An attacker could exploit this by using crafted variables during the execution of a system upgrade, potentially allowing them to overwrite or append arbitrary data to system files using root-level privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02979
CVE-2022-20789

Affected Products

Cisco Unified Communications Manager
Cisco Unified Communications Manager Session Management Edition