A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, and Cisco Prime License Manager could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper sanitization of user-supplied input. An attacker could exploit this vulnerability by sending a SOAP API request with crafted parameters to an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the underlying Linux operating system of the affected device.
History

Sat, 09 Nov 2024 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2021-04-08T04:05:35.307961Z

Updated: 2024-11-08T23:29:29.720Z

Reserved: 2020-11-13T00:00:00

Link: CVE-2021-1362

cve-icon Vulnrichment

Updated: 2024-08-03T16:11:17.346Z

cve-icon NVD

Status : Modified

Published: 2021-04-08T04:15:12.140

Modified: 2023-11-07T03:28:05.947

Link: CVE-2021-1362

cve-icon Redhat

No data.