Cisco Unified Intelligence Center
cpe:2.3:a:cisco:unified_intelligence_center:*:*:*:*:*:*:*, +1 more
- 12.5(1)SU3
- 12.5
- 15
- 12.6
A server-side request forgery (SSRF) vulnerability has been identified in the web-based management interface of Cisco Unified Intelligence Center. This vulnerability allows an unauthenticated, remote attacker to send arbitrary network requests from the affected device. The issue arises from improper input validation of certain HTTP requests.
Exploitation of this vulnerability could enable an attacker to conduct SSRF attacks, potentially allowing access to internal services or resources that are not normally exposed to external networks.
Cisco has released software updates to address this vulnerability. For Cisco Unified Intelligence Center, users can upgrade to version 12.5(1) SU ES05 or 12.6(2) ES05. For Cisco Unified Contact Center Express, users should migrate to a fixed release. Consult the Cisco Product Security Incident Response Team (PSIRT) for guidance on the upgrade process.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.