Description
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device.
Problem types
Server-Side Request Forgery (SSRF)
Product status
10.6(1)
10.5(1)SU1
10.6(1)SU3
12.0(1)
10.6(1)SU1
11.0(1)SU1
11.5(1)SU1
10.5(1)
11.6(1)
11.6(2)
12.5(1)
12.5(1)SU1
12.5(1)SU2
12.5(1)SU3
12.5(1)_SU03_ES01
12.5(1)_SU03_ES02
12.5(1)_SU02_ES03
12.5(1)_SU02_ES04
12.5(1)_SU02_ES02
12.5(1)_SU01_ES02
12.5(1)_SU01_ES03
12.5(1)_SU02_ES01
11.6(2)ES07
11.6(2)ES08
12.5(1)_SU01_ES01
12.0(1)ES04
12.5(1)ES02
12.5(1)ES03
11.6(2)ES06
12.5(1)ES01
12.0(1)ES03
12.0(1)ES01
11.6(2)ES05
12.0(1)ES02
11.6(2)ES04
11.6(2)ES03
11.6(2)ES02
11.6(2)ES01
10.6(1)SU3ES03
11.0(1)SU1ES03
10.6(1)SU3ES01
10.5(1)SU1ES10
11.5(1)SU1ES03
11.6(1)ES02
11.5(1)ES01
10.6(1)SU2
10.6(1)SU2ES04
11.6(1)ES01
10.6(1)SU3ES02
11.5(1)SU1ES02
11.5(1)SU1ES01
11.0(1)SU1ES02
12.5(1)_SU03_ES03
12.5(1)_SU03_ES04
12.5(1)_SU03_ES05
12.5(1)_SU03_ES06
11.6(1)
10.5(1)
11.0(1)
11.5(1)
12.0(1)
12.5(1)
11.0(2)
12.6(1)
12.5(1)SU
12.6(1)_ET
12.6(1)_ES05_ET
11.0(3)
12.6(2)
12.6(2)_504_Issue_ET
12.6.1_ExcelIssue_ET
12.6(2)_Permalink_ET
12.6.2_CSCwk19536_ET
12.6.2_CSCwm96922_ET
12.6.2_Amq_OOS_ET
12.5(2)ET_CSCwi79933
12.6(2)_ET
12.6.2_CSCwn48501_ET
References
sec.cloudapps.cisco.com/...visory/cisco-sa-cuis-ssrf-JSuDjeV (cisco-sa-cuis-ssrf-JSuDjeV)