Infosec.Pub
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
digicatM to blueteamsecEnglish · 24 days ago

Cisco Security Advisory: Cisco Unified Communications Products Remote Code Execution Vulnerability - "The Cisco PSIRT is aware of attempted exploitation of this vulnerability in the wild"

sec.cloudapps.cisco.com

external-link
message-square
0
link
fedilink
3
external-link

Cisco Security Advisory: Cisco Unified Communications Products Remote Code Execution Vulnerability - "The Cisco PSIRT is aware of attempted exploitation of this vulnerability in the wild"

sec.cloudapps.cisco.com

digicatM to blueteamsecEnglish · 24 days ago
message-square
0
link
fedilink
Cisco Security Advisory: Cisco Unified Communications Products Remote Code Execution Vulnerability
sec.cloudapps.cisco.com
external-link
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.  This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voice-rce-mORhqY4b
alert-triangle
You must log in or # to comment.

blueteamsec

blueteamsec

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !blueteamsec@infosec.pub

For [Blue|Purple] Teams in Cyber Defence - covering discovery, detection, response, threat intelligence, malware, offensive tradecraft and tooling, deception, reverse engineering etc.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 34 users / day
  • 110 users / week
  • 300 users / month
  • 929 users / 6 months
  • 224 local subscribers
  • 627 subscribers
  • 2.39K Posts
  • 183 Comments
  • Modlog
  • mods:
  • digicat
  • BE: 0.19.13
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org