CyberSec.Space Logo
Back to CVE Browser

CVE-2021-1362

HIGH
8.8
CVSS Severity Score
EPSS Score0.1490%
EPSS Percentile7.73th
PublishedApr 8, 2021
Last ModifiedNov 21, 2024

Vulnerability Description

A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, and Cisco Prime License Manager could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper sanitization of user-supplied input. An attacker could exploit this vulnerability by sending a SOAP API request with crafted parameters to an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the underlying Linux operating system of the affected device.

Affected Platforms (CPE)

πŸ“¦
Cisco

Prime License Manager

>= 10.5\(2\) and < 11.5\(1\)su9
πŸ“¦
Cisco

Unified Communications Manager

>= 10.5\(2\) and < 11.5\(1\)su9
πŸ“¦
Cisco

Unified Communications Manager

>= 10.5\(2\) and < 11.5\(1\)su9
πŸ“¦
Cisco

Unified Communications Manager

>= 12.0\(1\) and < 12.5\(1\)su4
πŸ“¦
Cisco

Unified Communications Manager

>= 12.0\(1\) and < 12.5\(1\)su4
πŸ“¦
Cisco

Unified Communications Manager Im \& Presence Service

>= 10.5\(2\) and < 11.5\(1\)su9
πŸ“¦
Cisco

Unified Communications Manager Im \& Presence Service

>= 12.0\(1\) and < 12.5\(1\)su4
πŸ“¦
Cisco

Unity Connection

>= 10.5\(2\) and < 11.5\(1\)su9
πŸ“¦
Cisco

Unity Connection

>= 12.0\(1\) and < 12.5\(1\)su4

References & Advisories

Related Vulnerabilities