Attackers exploit Cisco Unified CM flaw weeks after patch release
Summary
Cisco Unified CM has an actively exploited vulnerability that can let remote attackers gain root access. Cisco released patches on June 3 and advised customers to upgrade to fixed releases or temporarily disable the WebDialer service. Threat researchers say they first observed exploitation on June 23, using an unvetted proof of concept and file-write payloads. The issue affects enterprise voice, video, messaging, mobility, and conferencing environments that rely on Unified CM.
Classifications
industries
No industries detected
applications
Business Intelligence
AI Classifications
Labels
SaaS
Enterprise Software
Collaboration Software
Linked Companies
Cisco Systems, Inc.
$1B+