Description
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
12.5(1)SU2
12.5(1)SU1
12.5(1)
12.5(1)SU3
12.5(1)SU4
14
12.5(1)SU5
14SU1
12.5(1)SU6
14SU2
12.5(1)SU7
12.5(1)SU7a
14SU3
12.5(1)SU8
12.5(1)SU8a
15
15SU1
14SU4
14SU4a
15SU1a
12.5(1)SU9
15SU2
References
sec.cloudapps.cisco.com/...isory/cisco-sa-cucm-csrf-w762pRYd (cisco-sa-cucm-csrf-w762pRYd)