Code Injection in Cisco Systems, Inc products - CVE-2021-1362
Published: April 7, 2021
Unified Communications Manager (CallManager)
Cisco Unified Communications Manager Session Management Edition
Cisco Unified Communications Manager IM & Presence Service
Cisco Unity Connection
Cisco Prime License Manager
Cisco Systems, Inc
Description
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation in the SOAP API endpoint. A remote user can send a specially crafted SOAP API request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
External links
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-rce-pqVYwyb
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv35203
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu56491
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv41616
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv59434