QID 317410

Date Published: 2024-01-25

QID 317410: Cisco Unified Communications Products Remote Code Execution (RCE) Vulnerability (cisco-sa-cucm-rce-bWNzQcUm)

A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device.

Affected Products

Unified CM and Unified CM SME:
Version 11.5(1) prior to release 12.5(1)SU8 or ciscocm.v1_java_deserial-CSCwd64245.cop.sha512
Version 14 prior to release 14SU3 or ciscocm.v1_java_deserial-CSCwd64245.cop.sha512

Unified CM IM and P:
Version 11.5(1) prior to release 12.5(1)SU8 or ciscocm.cup-CSCwd64276_JavaDeserialization.cop.sha512
Version 14 prior to release 14SU3 or ciscocm.cup-CSCwd64276_JavaDeserialization.cop.sha512

Unity Connection:
Version 11.5(1) prior to release 12.5(1)SU8 or ciscocm.cuc.v1_java_deserial-CSCwd64292.k4.cop.sha512
Version 14 prior to release ciscocm.cuc.v1_java_deserial-CSCwd64292.k4.cop.sha512

QID Detection Logic (Authenticated):
The check matches the Cisco Unified Communications Product version retrieved via Unix Auth using " Active Master Version:" command.

A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the web services user

  • CVSS V3 rated as Critical - 10 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution

    Customers are advised to refer to cisco-sa-cucm-rce-bWNzQcUm for more information.

    CVEs related to QID 317410

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-cucm-rce-bWNzQcUm URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-rce-bWNzQcUm