CVE-2016-6426: Input Validation
The jspringsecurityswitchuser function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to create user accounts by visiting an unspecified web page, aka Bug IDs CSCuy75027 and CSCuy81653.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6426?
CVE-2016-6426 is considered a high severity vulnerability due to its potential for unauthorized account creation.
Which versions are affected by CVE-2016-6426?
CVE-2016-6426 affects Cisco Unified Intelligence Center versions 8.5.4 to 9.1(1) and Unified Contact Center Express versions 10.0(1) to 11.0(1).
How do I fix CVE-2016-6426?
To fix CVE-2016-6426, update affected Cisco software to the latest version that addresses this vulnerability.
Can CVE-2016-6426 be exploited remotely?
Yes, CVE-2016-6426 can be exploited remotely by attackers to create unauthorized user accounts.
What is the impact of exploiting CVE-2016-6426?
Exploitation of CVE-2016-6426 can lead to unauthorized access and potential abuse of user accounts within the affected Cisco systems.