Tuesday, March 4, 2025
HomeCyber Security NewsCisco Unified Communications Manager Flaw Let Attacker Launch SQL Injection Attacks

Cisco Unified Communications Manager Flaw Let Attacker Launch SQL Injection Attacks

Published on

SIEM as a Service

Follow Us on Google News

An SQL injection vulnerability was discovered in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME). 

Cisco Unified CM is used for handling voice and video calls, whereas Cisco Unified CM SME is used for session routing intelligence.

This SQL injection vulnerability allows an authenticated remote attacker to conduct SQL injection attacks on any affected system. However, Cisco has released software updates to fix this vulnerability.

CVE-2023-20211: SQL Injection Vulnerability

This vulnerability exists due to improper validation of user-supplied input. An attacker can authenticate as a read-only user into the application and exploit this vulnerability by sending crafted HTTP requests to an affected system.

The result of a successful exploitation results in reading or modifying the data in the system or performing privilege escalation. The CVSS score for this vulnerability is given as 8.1 (High).

Affected Products

Products that are affected due to this vulnerability include Cisco Unified CM and Cisco Unified CM SME. In addition, Cisco has also mentioned that the below products are not affected by this vulnerability.

  • Emergency Responder
  • Finesse
  • Hosted Collaboration Mediation Fulfillment (HCM-F)
  • Packaged Contact Center Enterprise (Packaged CCE)
  • Prime Collaboration Deployment
  • Prime License Manager (PLM)
  • SocialMiner
  • Unified Communications Manager IM & Presence Service (Unified CM IM&P)
  • Unified Contact Center Domain Manager (Unified CCDM)
  • Unified Contact Center Express (Unified CCX)
  • Unified Contact Center Management Portal (Unified CCMP)
  • Unified Intelligence Center
  • Unity Connection
  • Virtualized Voice Browser

Fixed in Version

Cisco Unified CM and Unified CM SME ReleaseFirst Fixed Release
11.5(1)Migrate to a fixed release.
12.5(1)12.5(1)SU8
14Apply patch file
ciscocm.V14SU3_CSCwe89928_sql-injection_C0194-1.cop.sha512.

Users of these products are recommended to upgrade to the latest version to prevent threat actors from exploiting this vulnerability.

Keep informed about the latest Cyber Security News by following us on GoogleNewsLinkedinTwitter, and Facebook.

Eswar
Eswar
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

Pathfinder AI – Hunters Announces New AI Capabilities for Smarter SOC Automation

Pathfinder AI expands Hunters' vision for AI-driven SOCs, introducing Agentic AI for autonomous investigation...

Google Secretly Tracks Android Devices Even Without User-Opened Apps

A recent technical study conducted by researchers at Trinity College Dublin has revealed that...

LLMjacking – Hackers Abuse GenAI With AWS NHIs to Hijack Cloud LLMs

In a concerning development, cybercriminals are increasingly targeting cloud-based generative AI (GenAI) services in...

Microsoft Strengthens Trust Boundary for VBS Enclaves

Microsoft has introduced a series of technical recommendations to bolster the security of Virtualization-Based...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Pathfinder AI – Hunters Announces New AI Capabilities for Smarter SOC Automation

Pathfinder AI expands Hunters' vision for AI-driven SOCs, introducing Agentic AI for autonomous investigation...

Google Secretly Tracks Android Devices Even Without User-Opened Apps

A recent technical study conducted by researchers at Trinity College Dublin has revealed that...

LLMjacking – Hackers Abuse GenAI With AWS NHIs to Hijack Cloud LLMs

In a concerning development, cybercriminals are increasingly targeting cloud-based generative AI (GenAI) services in...