漏洞分享 - Cisco Unified Communications Manager存在SQL Injection漏洞(CVE-2023-20010)
Cisco Unified Communications Manager存在SQL Injection漏洞
(CVE-2023-20010)
一、摘要
Cisco Unified Communications Manager存在SQL Injection漏洞(CVE-2023-20010),其允許取得授權的遠端攻擊者對Cisco Unified Communications Manager (Unified CM) 和Cisco Unified Communications Manager Session Management Edition (Unified CM SME) 進行SQL Injection攻擊。
二、存在風險
Cisco Unified Communications Manager存在SQL Injection漏洞(CVE-2023-20010),其允許取得授權的遠端攻擊者對Cisco Unified Communications Manager (Unified CM) 和Cisco Unified Communications Manager Session Management Edition (Unified CM SME) 進行SQL Injection攻擊,其影響系統或版本如下:
- Unified CM
- Unified CM SME
未受影響系統和版本如下:
- Emergency Responder
- Finesse
- Hosted Collaboration Mediation Fulfillment (HCM-F)
- Packaged Contact Center Enterprise (Packaged CCE)
- Prime Collaboration Deployment
- Prime License Manager (PLM)
- SocialMiner
- Unified Communications Manager IM & Presence Service (Unified CM IM&P)
- Unified Contact Center Domain Manager (Unified CCDM)
- Unified Contact Center Express (Unified CCX)
- Unified Contact Center Management Portal (Unified CCMP)
- Unified Intelligence Center
- Unity Connection
建議改善措施:請維護廠商協助更新或提供解決方案。