Cisco Unified Communications Manager是美国思科(Cisco)公司的一款统一通信系统中的呼叫处理组件。该组件提供了一种可扩展、可分布和高可用的企业IP电话呼叫处理解决方案。 Cisco Unified Communications Manager存在代码问题漏洞,该漏洞源于对特定HTTP请求的输入验证不当,可能导致未经身份验证的远程攻击者进行服务端请求伪造攻击,进而写入文件并提升至root权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Cisco | Cisco Unified Communications Manager | 14 |
affected |
14SU1 |
affected | ||
14SU2 |
affected | ||
14SU3 |
affected | ||
15 |
affected | ||
15SU1 |
affected | ||
14SU4 |
affected | ||
14SU4a |
affected | ||
| … +14 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Unified Communications Manager | 14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-20175 | 6.1 MEDIUM | Cisco Finesse File Inclusion Vulnerability |
| CVE-2026-20233 | 6.1 MEDIUM | Cisco Webex Meetings Cross-Site Scripting Vulnerability |
No comments yet