انتقل إلى المحتوى الرئيسي
English
logo
مستوى الخطورة: عالية
ثغرة

الرقم المرجعي: NCSC-TAD-2606-004CVSS 0

Critical SSRF Vulnerability in Cisco Unified Communications Manager

نوع التهديد:
غير متوفر
مستوى المشاركة (TLP):
CLEAR
CVE:
CVE-2026-20230

نظرة عامة

This is a critical Server-Side Request Forgery (SSRF) vulnerability affecting Cisco Unified Communications Manager products. An unauthenticated attacker can exploit this flaw by sending specially crafted HTTP requests to a vulnerable system with the WebDialer service enabled. Successful exploitation could allow the attacker to create files on the underlying operating system, potentially leading to privilege escalation and root-level access.

التقنيات المتأثرة

  • Cisco Unified CM and Unified CM SME systems running with the WebDialer service enabled.

إجراءات الحد من المخاطر والإجراءات الفورية

  1. 01

    Apply the latest security updates.

المراجع