cisco-sa-20191002-cucm-csrf: Multiple Cisco Unified Communications Products Cross-Site Request Forgery Vulnerability
A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections by the affected software. An attacker could exploit this vulnerability by persuading a targeted user to click a malicious link. A successful exploit could allow the attacker to send arbitrary requests that could change the password of a targeted user. An attacker could then take unauthorized actions on behalf of the targeted user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191002-cucm-csrf
Affected Software
Event History
Frequently Asked Questions
What is the Cisco Unified Communications Products Cross-Site Request Forgery vulnerability?
The Cisco Unified Communications Products Cross-Site Request Forgery (CSRF) vulnerability is a security flaw in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, and Cisco Unity Connection.
How severe is the Cisco Unified Communications Products Cross-Site Request Forgery vulnerability?
The severity of the Cisco Unified Communications Products Cross-Site Request Forgery vulnerability is medium with a severity score of 6.5.
Which Cisco products are affected by the Cross-Site Request Forgery vulnerability?
The Cross-Site Request Forgery vulnerability affects Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, and Cisco Unity Connection.
How can I fix the Cisco Unified Communications Products Cross-Site Request Forgery vulnerability?
To fix the Cisco Unified Communications Products Cross-Site Request Forgery vulnerability, apply the recommended patch files or upgrade to the specified versions according to the Cisco security advisory.
What is the Common Weakness Enumeration (CWE) ID for the Cisco Unified Communications Products Cross-Site Request Forgery vulnerability?
The Common Weakness Enumeration (CWE) ID for the Cisco Unified Communications Products Cross-Site Request Forgery vulnerability is CWE-352.