cbcvebase.
CVE-2022-20859
published 2022-07-06

CVE-2022-20859: A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence…

PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.17%
63.8th percentile
A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authenticated, remote attacker to perform certain administrative actions they should not be able to. This vulnerability is due to insufficient access control checks on the affected device. An attacker with read-only privileges could exploit this vulnerability by executing a specific vulnerable command on an affected device. A successful exploit could allow the attacker to perform a set of administrative actions they should not be able to.

Affected

5 ranges
VendorProductVersion rangeFixed in
ciscocisco_unified_communications_manager
ciscounified_communications_manager>= 14.0 < 14su214su2
ciscounified_communications_manager_im_and_presence_service>= 14.0 < 14.0su214.0su2
ciscounified_communications_products
ciscounity_connection>= 14.0 < 14su214su2

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit requires an authenticated user with read-only privileges executing a specific vulnerable command against the Disaster Recovery framework of affected Cisco Unified Communications products
  • Monitor for unexpected administrative actions performed by accounts that should only have read-only access on Cisco Unified CM, Unified CM IM&P, or Unity Connection — this may indicate exploitation of insufficient access control in the Disaster Recovery framework
  • Track Cisco Bug IDs CSCvz16246 and CSCwc12673 for patch status and affected version ranges across Unified CM, Unified CM IM&P, and Unity Connection
  • ·No workarounds are available; remediation requires applying Cisco-supplied software updates
  • ·The vulnerability is rooted in insufficient access control checks (CWE-284) within the Disaster Recovery framework, meaning privilege separation between read-only and administrative roles is not enforced correctly

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.