cbcvebase.
CVE-2023-20259
published 2023-10-04

CVE-2023-20259: A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to cause high CPU…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to cause high CPU utilization, which could impact access to the web-based management interface and cause delays with call processing. This API is not used for device management and is unlikely to be used in normal operations of the device. This vulnerability is due to improper API authentication and incomplete validation of the API request. An attacker could exploit this vulnerability by sending a crafted HTTP request to a specific API on the device. A successful exploit could allow the attacker to cause a denial of service (DoS) condition due to high CPU utilization, which could negatively impact user traffic and management access. When the attack stops, the device will recover without manual intervention.

Affected

18 ranges
VendorProductVersion rangeFixed in
ciscocisco_emergency_responder
ciscocisco_emergency_responder
ciscocisco_emergency_responder
ciscocisco_prime_collaboration_deployment
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager_im_and_presence_service
ciscocisco_unified_communications_manager_im_and_presence_service
ciscocisco_unity_connection
ciscoemergency_responder
ciscoprime_collaboration_deployment
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager_im_presence_service
ciscounified_communications_manager_im_presence_service
ciscounified_communications_products_unauthenticated
ciscounity_connection