Multiple vulnerabilities have been reported in the Cisco Unity Connection's web-based management interface that could allow a remote attacker to conduct server-side request forgery (SSRF) attacks through an affected system and execute arbitrary code on the targeted system, potentially resulting in complete system compromise.
Target Audience:
All organizations and individuals using Cisco Unity Connection.
Risk Assessment:
High risk of remote code execution, SSRF exploitation, privilege escalation.
Impact Assessment:
Execution of unauthorized code or commands, unauthorized access and disclosure of sensitive information.
The information provided herein is on "as is" basis, without warranty of any kind.