Thursday, January 30, 2025
HomeCyber Security NewsCisco Unified Communications Manager Flaw Let Attacker Launch SQL Injection Attacks

Cisco Unified Communications Manager Flaw Let Attacker Launch SQL Injection Attacks

Published on

SIEM as a Service

Follow Us on Google News

An SQL injection vulnerability was discovered in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME). 

Cisco Unified CM is used for handling voice and video calls, whereas Cisco Unified CM SME is used for session routing intelligence.

This SQL injection vulnerability allows an authenticated remote attacker to conduct SQL injection attacks on any affected system. However, Cisco has released software updates to fix this vulnerability.

CVE-2023-20211: SQL Injection Vulnerability

This vulnerability exists due to improper validation of user-supplied input. An attacker can authenticate as a read-only user into the application and exploit this vulnerability by sending crafted HTTP requests to an affected system.

The result of a successful exploitation results in reading or modifying the data in the system or performing privilege escalation. The CVSS score for this vulnerability is given as 8.1 (High).

Affected Products

Products that are affected due to this vulnerability include Cisco Unified CM and Cisco Unified CM SME. In addition, Cisco has also mentioned that the below products are not affected by this vulnerability.

  • Emergency Responder
  • Finesse
  • Hosted Collaboration Mediation Fulfillment (HCM-F)
  • Packaged Contact Center Enterprise (Packaged CCE)
  • Prime Collaboration Deployment
  • Prime License Manager (PLM)
  • SocialMiner
  • Unified Communications Manager IM & Presence Service (Unified CM IM&P)
  • Unified Contact Center Domain Manager (Unified CCDM)
  • Unified Contact Center Express (Unified CCX)
  • Unified Contact Center Management Portal (Unified CCMP)
  • Unified Intelligence Center
  • Unity Connection
  • Virtualized Voice Browser

Fixed in Version

Cisco Unified CM and Unified CM SME ReleaseFirst Fixed Release
11.5(1)Migrate to a fixed release.
12.5(1)12.5(1)SU8
14Apply patch file
ciscocm.V14SU3_CSCwe89928_sql-injection_C0194-1.cop.sha512.

Users of these products are recommended to upgrade to the latest version to prevent threat actors from exploiting this vulnerability.

Keep informed about the latest Cyber Security News by following us on GoogleNewsLinkedinTwitter, and Facebook.

Eswar
Eswar
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

New RDP Exploit Allows Attackers to Take Over Windows and Browser Sessions

Cybersecurity experts have uncovered a new exploit leveraging the widely used Remote Desktop Protocol...

New SMS-Based Phishing Tool ‘DevilTraff’ Enables Mass Cyber Attacks

Cybersecurity experts are sounding the alarm about a new SMS-based phishing tool, Devil-Traff, that...

DeepSeek Database Publicly Exposed Sensitive Information, Secret Keys & Logs

Experts at Wiz Research have identified a publicly exposed ClickHouse database belonging to DeepSeek,...

OPNsense 25.1 Released, What’s New!

The highly anticipated release of OPNsense 25.1 has officially arrived! Nicknamed "Ultimate Unicorn," this...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

New RDP Exploit Allows Attackers to Take Over Windows and Browser Sessions

Cybersecurity experts have uncovered a new exploit leveraging the widely used Remote Desktop Protocol...

New SMS-Based Phishing Tool ‘DevilTraff’ Enables Mass Cyber Attacks

Cybersecurity experts are sounding the alarm about a new SMS-based phishing tool, Devil-Traff, that...

DeepSeek Database Publicly Exposed Sensitive Information, Secret Keys & Logs

Experts at Wiz Research have identified a publicly exposed ClickHouse database belonging to DeepSeek,...