Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-20230

Опубликовано: 03 июн. 2026
Источник: nvd
CVSS3: 8.6
EPSS Средний

Описание

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.

This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root. Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:-:*:*:*
Версия от 14.0 (включая) до 14su6 (исключая)
cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:session_management:*:*:*
Версия от 14.0 (включая) до 14su6 (исключая)
cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:-:*:*:*
Версия от 15.0 (включая) до 15su4a (включая)
cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:session_management:*:*:*
Версия от 15.0 (включая) до 15su4a (включая)

EPSS

Процентиль: 99%
0.41694
Средний

8.6 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.6
github
2 месяца назад

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root. Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.

CVSS3: 8.6
fstec
2 месяца назад

Уязвимость службы WebDialer систем обработки вызовов Cisco Unified Communications Manager (Unified CM) и Cisco Unified Communications Manager Session Management Edition (Unified CM SME), позволяющая нарушителю осуществить SSRF-атаку

EPSS

Процентиль: 99%
0.41694
Средний

8.6 High

CVSS3

Дефекты

CWE-918