cisco-sa-20191002-ucm-secbypass: Cisco Unified Communications Manager Security Bypass Vulnerability
A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to bypass security restrictions. The vulnerability is due to improper handling of malformed HTTP methods. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected system. A successful exploit could allow the attacker to gain unauthorized access to the system.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191002-ucm-secbypass
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20191002-ucm-secbypass?
The severity of cisco-sa-20191002-ucm-secbypass is classified as critical due to the potential for unauthorized access.
How do I fix cisco-sa-20191002-ucm-secbypass?
To fix cisco-sa-20191002-ucm-secbypass, update your Cisco Unified Communications Manager or Session Management Edition to the latest patched version.
What exploitation method does cisco-sa-20191002-ucm-secbypass use?
cisco-sa-20191002-ucm-secbypass can be exploited by an unauthenticated remote attacker accessing the web-based interface.
What products are affected by cisco-sa-20191002-ucm-secbypass?
The affected products for cisco-sa-20191002-ucm-secbypass include Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition.
Is user authentication required to exploit cisco-sa-20191002-ucm-secbypass?
No, user authentication is not required to exploit cisco-sa-20191002-ucm-secbypass.