Impact
The vulnerability is a server‑side request forgery that allows an unauthenticated, remote attacker to send crafted HTTP requests to an affected Cisco Unified Communications Manager or its Unified CM Session Management Edition when the WebDialer service is enabled. Improper input validation of these requests permits the attacker to write files to the underlying operating system that could be used later to elevate privileges to root. Cisco has rated the vulnerability as Critical due to the full system compromise potential, and the issue is present only when WebDialer is active, a service that is disabled by default.
Affected Systems
Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition are impacted, but only installations where the WebDialer service is enabled are vulnerable. The service is disabled by default, so environments that have not explicitly enabled WebDialer are not affected, and no specific version details are provided.
Risk and Exploitability
The CVSS score of 8.6 and an EPSS score of 81% indicate a high severity with a very high likelihood of exploitation. This vulnerability is listed in the CISA KEV catalog, underscoring its real‑world exploitation risk. An attacker who can reach the affected device via the WebDialer interface can issue HTTP requests that result in arbitrary file writes, providing a direct path to privilege escalation on the CUCM host.
OpenCVE Enrichment