First published: Fri Mar 03 2023(Updated: )
Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these vulnerabilities.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Packaged Contact Center Enterprise | ||
Cisco Unified Contact Center Enterprise | ||
Cisco Unified Contact Center Express | ||
Cisco Unified Intelligence Center | <12.6\(2\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-20062 is a vulnerability in Cisco Unified Intelligence Center that allows an authenticated remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack.
An attacker can exploit CVE-2023-20062 by sending specially crafted requests to the affected system, allowing them to collect sensitive information or perform an SSRF attack.
CVE-2023-20062 has a severity rating of 4.3 (medium).
Cisco Unified Intelligence Center version up to and including 12.6(2) is affected by CVE-2023-20062.
Yes, Cisco plans to release software updates that address the vulnerabilities in Cisco Unified Intelligence Center.