Cisco Unified Communications Manager Cross-Site Request Forgery Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 4.3 Security Advisory

TL;DR 📌

A medium-severity Cross-Site Request Forgery (CSRF) vulnerability has been identified in Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME). An unauthenticated attacker could exploit this vulnerability by tricking a user into clicking a malicious link, potentially allowing the attacker to perform actions with the user’s privileges. There are no workarounds available, and affected users should upgrade to fixed software versions.

What happened 🕵️‍♂️

A vulnerability was discovered in the web-based management interface of Cisco Unified Communications Manager and Unified CM Session Management Edition. This vulnerability allows an unauthenticated remote attacker to conduct a CSRF attack, which could enable them to perform arbitrary actions at the privilege level of the affected user. The vulnerability arises from insufficient CSRF protections in the management interface.

Affected products 🖥️

The following products are affected by this vulnerability:

  • Cisco Unified Communications Manager (Unified CM)
  • Cisco Unified CM Session Management Edition (SME)

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
12.5 Migrate to a fixed release.
14 Migrate to a fixed release.
15 15SU3
1.0 Initial public release.
Cisco Unified CM and Unified CM SME 15SU3 12.5, 14

Workarounds 🧯

There are no workarounds available that address this vulnerability.

Risk in context 🎯

The CVSS score for this vulnerability is 4.3, which is categorized as Medium severity. The risk is primarily driven by the potential for an unauthenticated attacker to exploit the vulnerability through social engineering tactics, such as persuading a user to click on a malicious link. This could lead to unauthorized actions being performed on the affected device.

Fast facts ⚡

  • Vulnerability Type: Cross-Site Request Forgery (CSRF)
  • CVSS Score: 4.3 (Medium)
  • Exploitation: Requires user interaction; no authentication needed.
  • Impact: Potential unauthorized actions at user privilege level.
  • Workarounds: None available.

For leadership 🧭

Executive summary. An unauthenticated attacker who lures a logged-in Unified CM administrator into clicking a malicious link could trigger configuration changes on the call manager using that admin’s own session. There is no workaround, so this should be scheduled into the next available maintenance window rather than left for a routine patch cycle.

Why it matters:

  • The flaw sits in the web-based management interface of Unified Communications Manager and Unified CM Session Management Edition, the systems that control call routing and telephony configuration.
  • Exploitation needs no credentials from the attacker; it only needs a targeted user, potentially an administrator, to click a link while authenticated to the management interface.
  • Because the action runs at the victim’s privilege level, an admin session being tricked could result in unauthorised changes to call manager configuration.
  • No workaround exists, so exposure remains until the software is upgraded.

Now / Next / Later:

  • Now: Identify which Unified CM and Unified CM SME instances are running 12.5 or 14 trains and confirm their web admin interfaces, remind administrators not to click unsolicited links while logged into the management UI.
  • Next: Upgrade affected 12.5 and 14 deployments to a fixed release, and bring 15-train systems to 15SU3, since no workaround is available to mitigate risk in the meantime.
  • Later: Review admin access practices for Unified CM’s management interface, such as restricting it to a dedicated management network and using separate browser sessions for admin tasks, to reduce exposure to CSRF-style attacks going forward.