Cisco Unified Intelligence Center
cpe:2.3:a:cisco:unified_intelligence_center:*:*:*:*:*:*:*, +1 more
- <= 12.6
- <= 15.0
A vulnerability exists in the API subsystem of Cisco Unified Intelligence Center (CUIC) versions 12.6 and earlier, as well as 15.0, that could allow an authenticated, remote attacker to access sensitive information from the affected system. This issue arises from improper validation of requests to certain API endpoints, enabling a low-privileged user to view restricted information. Exploitation requires valid user credentials on the affected system.
Successful exploitation could allow a low-privileged user to access sensitive information on the affected system that is normally restricted.
Cisco has released software updates to address this vulnerability. Users should upgrade to Cisco Unified Intelligence Center version 15.0(01) ES202508 or a later release. For versions 12.6 and earlier, users should migrate to a fixed release.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.