Cisco Unified Communications Manager
cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:*:*:*
- < 15.0
- = 15.0
A command injection vulnerability has been identified in the command-line interface (CLI) of various Cisco Unified Communications products. This vulnerability allows an authenticated, local attacker to execute arbitrary commands on the underlying operating system of the affected device with root privileges. The issue arises from inadequate validation of user-supplied command arguments, enabling attackers to manipulate commands executed on the CLI. To exploit this vulnerability, an attacker must possess valid administrative credentials.
Exploitation of this vulnerability could lead to unauthorized execution of commands on the affected device's operating system as the root user.
Cisco has released software updates to address this vulnerability. Users are advised to consult the Cisco Security Advisories page for information on fixed releases and upgrade instructions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.