QID 317410
Date Published: 2024-01-25
QID 317410: Cisco Unified Communications Products Remote Code Execution (RCE) Vulnerability (cisco-sa-cucm-rce-bWNzQcUm)
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device.
Affected Products
Unified CM and Unified CM SME:
Version 11.5(1) prior to release 12.5(1)SU8 or ciscocm.v1_java_deserial-CSCwd64245.cop.sha512
Version 14 prior to release 14SU3 or ciscocm.v1_java_deserial-CSCwd64245.cop.sha512
Unified CM IM and P:
Version 11.5(1) prior to release 12.5(1)SU8 or ciscocm.cup-CSCwd64276_JavaDeserialization.cop.sha512
Version 14 prior to release 14SU3 or ciscocm.cup-CSCwd64276_JavaDeserialization.cop.sha512
Unity Connection:
Version 11.5(1) prior to release 12.5(1)SU8 or ciscocm.cuc.v1_java_deserial-CSCwd64292.k4.cop.sha512
Version 14 prior to release ciscocm.cuc.v1_java_deserial-CSCwd64292.k4.cop.sha512
QID Detection Logic (Authenticated):
The check matches the Cisco Unified Communications Product version retrieved via Unix Auth using " Active Master Version:" command.
A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the web services user
Customers are advised to refer to cisco-sa-cucm-rce-bWNzQcUm for more information.
- cisco-sa-cucm-rce-bWNzQcUm -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-rce-bWNzQcUm
CVEs related to QID 317410
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-cucm-rce-bWNzQcUm |
|