Cisco Packaged Contact Center是美国Cisco公司的一套联络中心解决方案。 Cisco Packaged Contact Center Enterprise和Cisco Unified Contact Center Enterprise存在服务端请求伪造漏洞,该漏洞源于对特定HTTP请求的输入验证不当,可能导致经过身份验证的远程攻击者通过受影响设备进行服务端请求伪造攻击,成功利用可发送源自受影响设备的任意网络请求。以下版本受到影响:Cisco Packaged Contact
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Cisco | Cisco Packaged Contact Center Enterprise | 12.5(1) |
affected |
11.0(1) |
affected | ||
12.0(1) |
affected | ||
11.0(2) |
affected | ||
11.5(1) |
affected | ||
10.5(1) |
affected | ||
10.5(2) |
affected | ||
11.6(2) |
affected | ||
| … +6 more rows | |||
| Cisco | Cisco Unified Contact Center Enterprise | 12.6(1)ES3 |
affected |
12.6(1)ES1 |
affected | ||
12.6(1) |
affected | ||
12.6(1)ES2 |
affected | ||
12.6(1)SecurityPatch |
affected | ||
12.5(1)ES1 |
affected | ||
12.5(1) |
affected | ||
12.6(1)ES4 |
affected | ||
| … +19 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Packaged Contact Center Enterprise | 12.5(1) | - |
|
| Cisco | Cisco Unified Contact Center Enterprise | 12.6(1)ES3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-20030 | 10.0 CRITICAL | Cisco Crosswork Security Hardening Release: August 2026 |
| CVE-2026-20358 | 10.0 CRITICAL | Cisco Crosswork Security Hardening Release: August 2026 |
| CVE-2026-20357 | 10.0 CRITICAL | Cisco Crosswork Security Hardening Release: August 2026 |
| CVE-2026-20317 | 10.0 CRITICAL | Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Authentic |
| CVE-2026-20315 | 10.0 CRITICAL | Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Access Co |
| CVE-2026-20231 | 9.9 CRITICAL | Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Neutraliz |
| CVE-2026-20359 | 9.9 CRITICAL | Cisco Crosswork Security Hardening Release: August 2026 |
| CVE-2026-20318 | 9.6 CRITICAL | Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Input Val |
| CVE-2026-20319 | 7.5 HIGH | Cisco Secure Workload Software Security Hardening Release August 2026 - Buffer Management |
| CVE-2026-20320 | 7.5 HIGH | Cisco BroadWorks 输入验证错误漏洞 |
| CVE-2026-20327 | 6.5 MEDIUM | Cisco Unified Intelligence Center SQL Injection Vulnerability |
| CVE-2026-20302 | 6.1 MEDIUM | Cisco RoomOS Stack Overflow Vulnerability |
| CVE-2026-20232 | 5.4 MEDIUM | Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability |
| CVE-2026-20177 | 5.3 MEDIUM | Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability |
No comments yet