Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-1355

Опубликовано: 20 янв. 2021
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) and could allow an attacker to conduct SQL injection attacks on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:*:*:*:*
Версия до 11.5\(1\)su9 (исключая)
cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:session_management:*:*:*
Версия до 11.5\(1\)su9 (исключая)
cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:*:*:*:*
Версия от 12.0 (включая) до 12.0\(1\)su4 (исключая)
cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:session_management:*:*:*
Версия от 12.0 (включая) до 12.0\(1\)su4 (исключая)
cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:*:*:*:*
Версия от 12.5 (включая) до 12.5\(1\)su4 (исключая)
cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:session_management:*:*:*
Версия от 12.5 (включая) до 12.5\(1\)su4 (исключая)
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:*:*:*:*:*:*:*:*
Версия до 11.5\(1\)su9 (исключая)
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:*:*:*:*:*:*:*:*
Версия от 12.0 (включая) до 12.5\(1\)su4 (исключая)

EPSS

Процентиль: 60%
0.004
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-35
CWE-89

Связанные уязвимости

github
больше 3 лет назад

Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) and could allow an attacker to conduct SQL injection attacks on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 6.5
fstec
около 5 лет назад

Уязвимость веб-интерфейса управления системы обработки вызовов Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), позволяющая нарушителю выполнить произвольные SQL-запросы

EPSS

Процентиль: 60%
0.004
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-35
CWE-89