PT-2022-6669 · Cisco · Cisco Unified Communications Manager+1

·

CVE-2023-20116

·

Published

2022-10-27

·

Updated

2024-01-25

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco Unified Communications Manager versions (affected versions not specified) Cisco Unified Communications Manager Session Management Edition versions (affected versions not specified)
Description A vulnerability in the Administrative XML Web Service (AXL) API could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This issue is due to insufficient validation of user-supplied input to the web UI of the Self Care Portal. An attacker could exploit this by sending crafted HTTP input to an affected device, potentially causing a DoS condition.
Recommendations For Cisco Unified Communications Manager, update to a version that addresses the insufficient validation of user-supplied input. For Cisco Unified Communications Manager Session Management Edition, update to a version that addresses the insufficient validation of user-supplied input. As a temporary workaround, consider restricting access to the Administrative XML Web Service (AXL) API to minimize the risk of exploitation.

Fix

Infinite Loop

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03219
CVE-2023-20116

Affected Products

Cisco Unified Communications Manager
Cisco Unified Communications Manager Session Management Edition