cbcvebase.
CVE-2021-1362
published 2021-04-08

CVE-2021-1362: A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco…

PriorityP262high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.71%
84.3th percentile
A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, and Cisco Prime License Manager could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper sanitization of user-supplied input. An attacker could exploit this vulnerability by sending a SOAP API request with crafted parameters to an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the underlying Linux operating system of the affected device.

Affected

9 ranges
VendorProductVersion rangeFixed in
ciscocisco_unity_connection
ciscoprime_license_manager>= 10.5\(2\) < 11.5\(1\)su911.5\(1\)su9
ciscounified_communications_manager>= 10.5\(2\) < 11.5\(1\)su911.5\(1\)su9
ciscounified_communications_manager>= 12.0\(1\) < 12.5\(1\)su412.5\(1\)su4
ciscounified_communications_manager_im_presence_service>= 10.5\(2\) < 11.5\(1\)su911.5\(1\)su9
ciscounified_communications_manager_im_presence_service>= 12.0\(1\) < 12.5\(1\)su412.5\(1\)su4
ciscounified_communications_products
ciscounity_connection>= 10.5\(2\) < 11.5\(1\)su911.5\(1\)su9
ciscounity_connection>= 12.0\(1\) < 12.5\(1\)su412.5\(1\)su4

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for crafted SOAP API requests with anomalous or unsanitized parameters sent to the affected Cisco Unified Communications products' SOAP API endpoint
  • Alert on unexpected root-level process execution originating from the Cisco Unified Communications Manager, IM & Presence Service, Unity Connection, or Prime License Manager application processes on the underlying Linux OS
  • ·Exploitation requires authentication; monitor for authenticated sessions making unusual SOAP API calls, as the attacker must have valid credentials before exploiting this RCE vulnerability
  • ·Affected products span multiple Cisco UC platforms tracked under Bug IDs CSCvu56491, CSCvv35203, and CSCvv41616; ensure detection coverage applies to all: Unified CM, Unified CM SME, IM & Presence Service, Unity Connection, and Prime License Manager
  • ·No workarounds are available; detection must rely on network/host-based monitoring until patching is applied

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.