Impact
A vulnerability exists in the web‑based management interface of Cisco Unified Contact Center Express. The interface does not sufficiently validate user‑supplied input, allowing an unauthenticated, remote attacker to inject malicious code into specific pages. A successful exploit could enable the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser‑based information, as described in the advisory.
Affected Systems
Cisco Unified Contact Center Express is affected. The advisory does not specify version numbers, so all deployed instances should be considered vulnerable unless verified otherwise.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score is below 1 %, implying low likelihood of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can launch the exploit remotely without authentication, using the publicly accessible management interface.
OpenCVE Enrichment