CyberSec.Space Logo
CVEブラウザに戻る

CVE-2021-1362

HIGH
8.8
CVSS Severity Score
EPSS Score0.1490%
EPSS Percentile7.73th
Published2021年4月8日
Last Modified2024年11月21日

Vulnerability Description

A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, and Cisco Prime License Manager could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper sanitization of user-supplied input. An attacker could exploit this vulnerability by sending a SOAP API request with crafted parameters to an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the underlying Linux operating system of the affected device.

Affected Platforms (CPE)

📦
Cisco

Prime License Manager

>= 10.5\(2\) and < 11.5\(1\)su9
📦
Cisco

Unified Communications Manager

>= 10.5\(2\) and < 11.5\(1\)su9
📦
Cisco

Unified Communications Manager

>= 10.5\(2\) and < 11.5\(1\)su9
📦
Cisco

Unified Communications Manager

>= 12.0\(1\) and < 12.5\(1\)su4
📦
Cisco

Unified Communications Manager

>= 12.0\(1\) and < 12.5\(1\)su4
📦
Cisco

Unified Communications Manager Im \& Presence Service

>= 10.5\(2\) and < 11.5\(1\)su9
📦
Cisco

Unified Communications Manager Im \& Presence Service

>= 12.0\(1\) and < 12.5\(1\)su4
📦
Cisco

Unity Connection

>= 10.5\(2\) and < 11.5\(1\)su9
📦
Cisco

Unity Connection

>= 12.0\(1\) and < 12.5\(1\)su4

References & Advisories

関連する脆弱性情報