Логотип exploitDog
bind:CVE-2022-20859
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-20859

Количество 3

Количество 3

nvd логотип

CVE-2022-20859

больше 3 лет назад

A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authenticated, remote attacker to perform certain administrative actions they should not be able to. This vulnerability is due to insufficient access control checks on the affected device. An attacker with read-only privileges could exploit this vulnerability by executing a specific vulnerable command on an affected device. A successful exploit could allow the attacker to perform a set of administrative actions they should not be able to.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-vjcc-9q9g-593v

больше 3 лет назад

A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authenticated, remote attacker to perform certain administrative actions they should not be able to. This vulnerability is due to insufficient access control checks on the affected device. An attacker with read-only privileges could exploit this vulnerability by executing a specific vulnerable command on an affected device. A successful exploit could allow the attacker to perform a set of administrative actions they should not be able to.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2022-04291

больше 3 лет назад

Уязвимость функции Disaster Recovery систем обработки вызовов Cisco Unified Communications Manager, Cisco Unified Communications Manager IM & Presence Service, интегрированной системы обмена сообщениями Cisco Unity Connection, позволяющая нарушителю выполнить произвольные команды с привилегиями администратора

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-20859

A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authenticated, remote attacker to perform certain administrative actions they should not be able to. This vulnerability is due to insufficient access control checks on the affected device. An attacker with read-only privileges could exploit this vulnerability by executing a specific vulnerable command on an affected device. A successful exploit could allow the attacker to perform a set of administrative actions they should not be able to.

CVSS3: 6.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-vjcc-9q9g-593v

A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authenticated, remote attacker to perform certain administrative actions they should not be able to. This vulnerability is due to insufficient access control checks on the affected device. An attacker with read-only privileges could exploit this vulnerability by executing a specific vulnerable command on an affected device. A successful exploit could allow the attacker to perform a set of administrative actions they should not be able to.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-04291

Уязвимость функции Disaster Recovery систем обработки вызовов Cisco Unified Communications Manager, Cisco Unified Communications Manager IM & Presence Service, интегрированной системы обмена сообщениями Cisco Unity Connection, позволяющая нарушителю выполнить произвольные команды с привилегиями администратора

CVSS3: 6.5
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу