cisco-sa-20190904-unified-ccx-ssrf: Cisco Unified Contact Center Express Request Processing Server-Side Request Forgery Vulnerability
A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on a targeted system. The vulnerability is due to improper validation of user-supplied input on the affected system. An attacker could exploit this vulnerability by sending the user of the web application a crafted request. If the request is processed, the attacker could access the system and perform unauthorized actions. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190904-unified-ccx-ssrf
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20190904-unified-ccx-ssrf?
The severity of cisco-sa-20190904-unified-ccx-ssrf is classified as high due to its potential for unauthorized access and server-side request forgery.
How do I fix cisco-sa-20190904-unified-ccx-ssrf?
To fix cisco-sa-20190904-unified-ccx-ssrf, apply the latest security patch provided by Cisco for Unified Contact Center Express.
What systems are affected by cisco-sa-20190904-unified-ccx-ssrf?
cisco-sa-20190904-unified-ccx-ssrf affects the Cisco Unified Contact Center Express software.
Who can exploit cisco-sa-20190904-unified-ccx-ssrf?
An unauthenticated remote attacker can exploit cisco-sa-20190904-unified-ccx-ssrf to bypass access controls.
What kind of attack does cisco-sa-20190904-unified-ccx-ssrf enable?
cisco-sa-20190904-unified-ccx-ssrf enables a server-side request forgery (SSRF) attack.