Advertisement






Cisco Unified Contact Center Express Privilege Escalation

CVE Category Price Severity
CVE-2020-3385 CWE-269 $10,000 High
Author Risk Exploitation Type Date
Unknown High Local 2020-02-25
CPE
cpe:cpe:/a:cisco:cisco_unified_contact_center_express
CVSS EPSS EPSSP
CVSS:6.5/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H 0.0219 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2020020129

Below is a copy:

Cisco Unified Contact Center Express Privilege Escalation
I've quoted the Cisco summary below as it's pretty accurate.

tl;dr is an admin user on the web console can gain command execution
and then escalate to root. If this is an issue in your environment,
then please patch.

Thanks to Cisco PSIRT who were responsive and professional.

Shouts to Andrew, Dave and Senad, Pedro R - if that's still even a
thing on advisories.

Ref: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-privesc-Zd7bvwyf

"Summary

A vulnerability in the Administration Web Interface of Cisco Unified
Contact Center Express (Unified CCX) could allow an authenticated,
remote attacker to upload arbitrary files and execute commands on the
underlying operating system. To exploit this vulnerability, an
attacker needs valid Administrator credentials.

The vulnerability is due to insufficient restrictions for the content
uploaded to an affected system. An attacker could exploit this
vulnerability by uploading arbitrary files containing operating system
commands that will be executed by an affected system. A successful
exploit could allow the attacker to execute arbitrary commands with
the privileges of the web interface and then elevate their privileges
to root."

cheers,
 Jamie

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.