QID 316923
Date Published: 2021-04-12
QID 316923: Cisco Unified Communications Manager IM and Presence Service Remote Code Execution Vulnerability(cisco-sa-cucm-rce-pqVYwyb)
A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager IM Presence Service
could allow an authenticated,
remote attacker to execute arbitrary code on an affected device.
Affected Products
Cisco products if they are running a vulnerable software release:
Unified Communications Manager IM Presence Service (Unified CM IMP)
QID Detection Logic (Authenticated):
The check matches the Cisco Unified Communications Product version retrieved via Unix Auth using " Active Master Version:" command.
A successful exploit could allow the attacker to execute arbitrary code with root privileges on the underlying Linux operating system of the affected device.
Customers are advised to refer to cisco-sa-cucm-rce-pqVYwyb for more information.
- cisco-sa-cucm-rce-pqVYwyb -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-rce-pqVYwyb
CVEs related to QID 316923
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-cucm-rce-pqVYwyb |
|