Cisco Warns of Available PoC for Critical Unified CM Vulnerability
Summary
Cisco has released patches for a critical Unified CM vulnerability that could let an attacker gain root privileges on affected appliances. The company says proof-of-concept exploit code already exists, which increases the risk for organizations running the WebDialer service. Cisco also fixed two medium-severity issues in Webex Meetings and Finesse that could support XSS attacks or arbitrary file loading through malicious links. The Unified CM issue is resolved in version 14SU6, with fixes planned for version 15SU5 in September. These updates create an immediate security-hardening and patching task for enterprises using Cisco collaboration software.
Classifications
industries
No industries detected
applications
Business Intelligence
AskAI Classifications
Labels
SaaS
Enterprise Software
Collaboration Software
Linked Companies
Cisco
$1B+