Description
A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to conduct SSRF attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device.
Problem types
Server-Side Request Forgery (SSRF)
Product status
12.5(1)
12.5(1)SU1
12.5(1)SU2
12.5(1)SU3
12.5(1)SU4
14
12.5(1)SU5
14SU1
12.5(1)SU6
14SU2
12.5(1)SU7
14SU3
12.5(1)SU8
14SU3a
12.5(1)SU8a
15
15SU1
14SU4
12.5(1)SU9
15SU2
15SU3
References
sec.cloudapps.cisco.com/.../cisco-sa-unity-rce-ssrf-hENhuASy (cisco-sa-unity-rce-ssrf-hENhuASy)