Cisco.UCM.Information.Disclosure

description-logoDescription

This indicates an attack attempt to exploit an Information Disclosure vulnerability in Cisco UCM devices.
The vulnerability is due to insufficient validation of user supplied inputs in the application. A remote attacker may be able to exploit this to read arbitrary files within the context of the application, via a crafted request.

affected-products-logoAffected Products

Cisco UCM

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems

recomended-action-logoRecommended Actions

Currently we are unaware of any vendor supplied patch or updates available for this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2021-05-11 18.078 Default_action:pass:drop
2021-05-04 18.072

References

30237