漏洞分享 - Cisco Unified Communications Manager存在SQL Injection漏洞(CVE-2023-20010)

                  



Cisco Unified Communications Manager存在SQL Injection漏洞
(CVE-2023-20010)

一、摘要

        Cisco Unified Communications Manager存在SQL Injection漏洞(CVE-2023-20010),其允許取得授權的遠端攻擊者對Cisco Unified Communications Manager (Unified CM) 和Cisco Unified Communications Manager Session Management Edition (Unified CM SME) 進行SQL Injection攻擊。

、存在風險

        Cisco Unified Communications Manager存在SQL Injection漏洞(CVE-2023-20010),其允許取得授權的遠端攻擊者對Cisco Unified Communications Manager (Unified CM) 和Cisco Unified Communications Manager Session Management Edition (Unified CM SME) 進行SQL Injection攻擊,其影響系統或版本如下:

  • Unified CM
  • Unified CM SME
  
        未受影響系統和版本如下:
  • Emergency Responder
  • Finesse
  • Hosted Collaboration Mediation Fulfillment (HCM-F)
  • Packaged Contact Center Enterprise (Packaged CCE)
  • Prime Collaboration Deployment
  • Prime License Manager (PLM)
  • SocialMiner
  • Unified Communications Manager IM & Presence Service (Unified CM IM&P)
  • Unified Contact Center Domain Manager (Unified CCDM)
  • Unified Contact Center Express (Unified CCX)
  • Unified Contact Center Management Portal (Unified CCMP)
  • Unified Intelligence Center
  • Unity Connection

        建議改善措施:請維護廠商協助更新或提供解決方案

    
   情資報告連結:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-sql-rpPczR8n?emailclick=CNSemail

這個網誌中的熱門文章

漏洞分享 - Fortinet 產品存在多個漏洞

-->

漏洞分享 - Fortinet 產品存在多個漏洞

-->

漏洞分享 - Fortinet 產品存在多個漏洞

-->

案例分享-某企業AD上百組帳號大量登入失敗導致鎖定事件

-->

資安威脅趨勢 - 醫院遭CrazyHunter勒索軟體持續攻擊

-->

漏洞更新 - VMware修補vCenter Server heap-overflow和privilege escalation漏洞

-->

漏洞分享 - Fortinet 產品存在多個漏洞

-->

漏洞分享 - Fortinet 產品多個漏洞

-->

漏洞分享 - Fortinet 產品存在多個漏洞

-->

漏洞分享 - Fortinet 產品存在多個漏洞

-->