Cisco Unity Connection
cpe:2.3:a:cisco:unity_connection:*:*:*:*:*:*:*
- <= 12.5
- >= 14, < 14SU6
- >= 15, < 15SU4
Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. These vulnerabilities arise from improper input sanitization in the web-based management interface, enabling an attacker with valid administrative credentials to exploit the issue by sending a crafted HTTPS request.
Exploitation of these vulnerabilities could lead to unauthorized access to sensitive files on the affected system.
Cisco has released software updates to address these vulnerabilities. Users should upgrade to version 14SU6 or 15SU4, depending on their current release. For those on version 12.5 or earlier, a migration to a fixed release is recommended.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.