Cisco Unified Communications Manager IM & Presence Service Cross-Site Scripting Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 6.1 Security Advisory

TL;DR 📌

A cross-site scripting (XSS) vulnerability has been identified in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service. This flaw could allow an unauthenticated remote attacker to execute arbitrary script code, potentially compromising sensitive information. Cisco has released fixed software versions, and there are no workarounds available.

What happened 🕵️‍♂️

A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) was discovered. This vulnerability arises from improper validation of user-supplied input, enabling an attacker to conduct a cross-site scripting (XSS) attack. By persuading a user to click on a malicious link, an attacker could execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.

Affected products 🖥️

The vulnerability affects Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) across all device configurations.

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
12.5 Migrate to a fixed release.
14 Migrate to a fixed release.
15 15SU3
1.0 Initial public release.
Cisco Unified CM IM&P 15SU3 12.5, 14

Workarounds 🧯

There are no workarounds available to mitigate this vulnerability.

Risk in context 🎯

The highest CVSS score for this vulnerability is 6.1, categorizing it as Medium severity. The exposure is primarily driven by the fact that the attack can be executed remotely without authentication, posing a risk to users of the web-based management interface. While there is no immediate evidence of exploitation, the potential for sensitive information exposure remains a concern.

Fast facts ⚡

  • Vulnerability Type: Cross-Site Scripting (XSS)
  • CVSS Score: 6.1 (Medium)
  • Exploitation: Requires user interaction (clicking a link)
  • No workarounds available

For leadership 🧭

Executive summary. An unauthenticated attacker can run arbitrary script in the Unified Communications Manager IM & Presence Service management interface by luring an admin or user into clicking a malicious link, risking exposure of session or credential data from that page. There’s no workaround, so remediation depends entirely on scheduling the upgrade; treat it as a normal patch-cycle item given the medium severity and no known exploitation.

Why it matters:

  • The flaw sits in the web-based management interface of Unified CM IM&P, a component typically used by administrators, so a successful click could expose admin session or browser data on a system that controls presence and messaging services.
  • No authentication is required to trigger the attack — only getting a user to click a crafted link — which lowers the bar compared with flaws needing valid credentials.
  • Cisco has published no workaround, meaning the only mitigation until upgrade is user caution around links to the management interface.
  • Affected releases span 12.5 and 14 (both requiring migration) and 15 (fixed in 15SU3), so most currently deployed trains need action.

Now / Next / Later:

  • Now: Warn administrators and users of the Unified CM IM&P web interface not to click unsolicited or unexpected links pointing to that management console.
  • Next: Plan and schedule the upgrade to 15SU3, or migrate 12.5/14 deployments to a fixed release, in the next available change window.
  • Later: Add Cisco Unified CM IM&P to routine patch-tracking so future advisories for this interface are picked up and scheduled without relying on ad-hoc user warnings.