๐Ÿ” CVE Alert

CVE-2023-20108

HIGH 7.5
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability in the XCP Authentication Service of the Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to cause a temporary service outage for all Cisco Unified CM IM&P users who are attempting to authenticate to the service, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted login message to the affected device. A successful exploit could allow the attacker to cause an unexpected restart of the authentication service, preventing new users from successfully authenticating. Exploitation of this vulnerability does not impact Cisco Unified CM IM&P users who were authenticated prior to an attack.

CWE CWE-789
Vendor cisco
Product cisco unified communications manager im and presence service
Ecosystems
Industries
NetworkingTelecommunications
Published Jun 28, 2023
Last Updated Aug 2, 2024
Stay Ahead of the Next One

Get instant alerts for cisco cisco unified communications manager im and presence service

Be the first to know when new high vulnerabilities affecting cisco cisco unified communications manager im and presence service are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

Cisco / Cisco Unified Communications Manager IM and Presence Service
10.5(1) 10.5(2) 10.5(2a) 10.5(2b) 10.5(2)SU3 10.5(2)SU2a 10.5(2)SU4a 10.5(2)SU4 10.5(1)SU3 10.5(1)SU1 10.5(2)SU1 10.5(2)SU2 10.5(1)SU2 11.5(1) 11.5(1)SU1 11.5(1)SU2 11.5(1)SU3 11.5(1)SU3a 11.5(1)SU4 11.5(1)SU5 11.5(1)SU5a 11.5(1)SU6 11.5(1)SU7 11.5(1)SU8 11.5(1)SU9 11.5(1)SU10 11.5(1)SU11 11.0(1) 11.0(1)SU1 12.5(1) 12.5(1)SU1 12.5(1)SU2 12.5(1)SU3 12.5(1)SU4 12.5(1)SU5 12.5(1)SU6 14 14SU1 14SU2 14SU2a 10.0(1) 10.0(1)SU1 10.0(1)SU2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
sec.cloudapps.cisco.com: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-imp-dos-49GL7rzT