OS command injection in Cisco Unity Express - CVE-2018-15381

 

OS command injection in Cisco Unity Express - CVE-2018-15381

Published: November 7, 2018 / Updated: November 8, 2018


Vulnerability identifier: #VU15768
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-15381
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to insecure deserialization of user-supplied content. A remote unauthenticated attacker can send a malicious serialized Java object to the listening Java Remote Method Invocation (RMI) service and execute arbitrary shell commands on the device with root privileges.


Affected software

Cisco Unity Express

How to mitigate CVE-2018-15381

Update to version 9.0.6.

Cisco Unity Express - update to 9.0.6

External References

Related Security Bulletins