Attackers exploit Cisco Unified CM flaw weeks after patch release

General News

Summary

Cisco Unified CM has an actively exploited vulnerability that can let remote attackers gain root access. Cisco released patches on June 3 and advised customers to upgrade to fixed releases or temporarily disable the WebDialer service. Threat researchers say they first observed exploitation on June 23, using an unvetted proof of concept and file-write payloads. The issue affects enterprise voice, video, messaging, mobility, and conferencing environments that rely on Unified CM.

Classifications

industries
No industries detected
applications
Business Intelligence

AI Classifications

Labels
SaaS Enterprise Software Collaboration Software

Linked Companies