Impact
The vulnerability arises from improper input validation for certain HTTP requests in Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise. An authenticated attacker can craft a malicious HTTP request to the device, tricking it into performing arbitrary network calls on the attacker’s behalf. This introduces a server‑side request forgery weakness (CWE‑918). The compromise could allow the attacker to reach internal or external resources, potentially exposing sensitive data, executing network‑level reconnaissance, or extending lateral movement. The impact is limited to the device from which the request originates and requires valid user credentials.
Affected Systems
Both Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise are affected. The advisory does not specify individual software versions; thus any installation of these products remains vulnerable until patched.
Risk and Exploitability
With a CVSS score of 5.0, the vulnerability is classified as moderate. Because the exploit requires authentication, the risk is constrained to accounts with administrative or privileged access to the affected device. EPSS data is not available, and the vulnerability is not listed in CISA KEV, indicating no known large‑scale exploitation yet. Nonetheless, a successful SSRF can be leveraged to breach internal networks or gather reconnaissance information, so caution is warranted.
OpenCVE Enrichment