
- الصفحة الرئيسية
- نشرات التهديدات
- NCSC-TAD-2606-004
NCSC-TAD-2606-004
مستوى الخطورة: عالية
ثغرة
الرقم المرجعي: NCSC-TAD-2606-004CVSS 0
Critical SSRF Vulnerability in Cisco Unified Communications Manager
- نوع التهديد:
- غير متوفر
- مستوى المشاركة (TLP):
- CLEAR
- CVE:
- CVE-2026-20230
نظرة عامة
This is a critical Server-Side Request Forgery (SSRF) vulnerability affecting Cisco Unified Communications Manager products. An unauthenticated attacker can exploit this flaw by sending specially crafted HTTP requests to a vulnerable system with the WebDialer service enabled. Successful exploitation could allow the attacker to create files on the underlying operating system, potentially leading to privilege escalation and root-level access.
التقنيات المتأثرة
- Cisco Unified CM and Unified CM SME systems running with the WebDialer service enabled.
إجراءات الحد من المخاطر والإجراءات الفورية
- 01
Apply the latest security updates.

