Cisco Unity Connection
cpe:2.3:a:cisco:unity_connection:*:*:*:*:*:*:*
- <= 12.5
- <= 14.0
- <= 15.0
A server-side request forgery (SSRF) vulnerability has been identified in the web UI of Cisco Unity Connection Web Inbox. This vulnerability allows an unauthenticated, remote attacker to send arbitrary network requests from the affected device. The issue arises from improper input validation of certain HTTP requests. Exploitation of this vulnerability could enable an attacker to conduct SSRF attacks, potentially accessing internal services or resources from the perspective of the affected device.
Exploitation of this vulnerability could allow an attacker to perform server-side request forgery (SSRF) attacks, sending arbitrary network requests from the affected device.
Users can upgrade to Cisco Unity Connection releases 14SU5 or 15SU4 to address this vulnerability. For Cisco Unity Connection 15.0, a specific patch is available. Instructions for downloading this patch are included in the advisory.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.