cisco-sa-uccx-multi-UhOTvPGL: Cisco Unified Contact Center Express Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack or execute arbitrary code on an affected device. To exploit these vulnerabilities, the attacker must have valid administrative credentials.For more information about these vulnerabilities, see the Details section of this advisory.Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-multi-UhOTvPGL
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-uccx-multi-UhOTvPGL?
The severity of cisco-sa-uccx-multi-UhOTvPGL is high due to the potential for remote code execution and stored cross-site scripting attacks.
How do I fix cisco-sa-uccx-multi-UhOTvPGL?
To fix cisco-sa-uccx-multi-UhOTvPGL, apply the latest updates and patches released by Cisco for the Unified Contact Center Express.
Who is affected by cisco-sa-uccx-multi-UhOTvPGL?
Organizations using the web-based management interface of Cisco Unified Contact Center Express are affected by cisco-sa-uccx-multi-UhOTvPGL.
What types of attacks are possible with cisco-sa-uccx-multi-UhOTvPGL?
cisco-sa-uccx-multi-UhOTvPGL allows for stored cross-site scripting (XSS) attacks and arbitrary code execution on affected devices.
Do I need to be authenticated to exploit cisco-sa-uccx-multi-UhOTvPGL?
Yes, an attacker must be authenticated to exploit cisco-sa-uccx-multi-UhOTvPGL.