Cisco Unified Communications Manager Stored Cross-Site Scripting Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 4.8 Security Advisory

TL;DR 📌

A stored cross-site scripting (XSS) vulnerability has been identified in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME). This vulnerability allows an authenticated remote attacker to execute arbitrary script code, potentially accessing sensitive information. Cisco has released fixed software updates, but no workarounds are available.

What happened 🕵️‍♂️

A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated attacker to conduct a cross-site scripting (XSS) attack. This occurs because the interface fails to properly validate user input, enabling the injection of malicious code. Successful exploitation could lead to the execution of arbitrary scripts in the context of the affected interface, compromising sensitive, browser-based information.

Affected products 🖥️

The following products are affected by this vulnerability:

  • Cisco Unified Communications Manager (Unified CM)
  • Cisco Unified Communications Manager Session Management Edition (Unified CM SME)

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
12.5 Migrate to a fixed release.
14 Migrate to a fixed release.
15 15SU3
1.0 Initial public release.
Cisco Unified CM and Unified CM SME 15SU3 12.5, 14

Workarounds 🧯

There are no workarounds available for this vulnerability.

Risk in context 🎯

With a CVSS score of 4.8, this vulnerability is rated as Medium severity. The risk is primarily driven by the need for valid administrative credentials for exploitation, which limits exposure to authenticated users. However, the potential for sensitive information access remains a concern, especially in environments where administrative access is prevalent.

Fast facts ⚡

  • Vulnerability Type: Stored Cross-Site Scripting (XSS)
  • CVSS Score: 4.8 (Medium)
  • Exploitation: Requires valid administrative credentials
  • Workarounds: None available
  • Fixed Software: Available for specified versions

For leadership 🧭

Executive summary. Cisco Unified Communications Manager and its Session Management Edition have a stored XSS flaw in the admin web interface, exploitable only by someone who already holds valid administrative credentials. There is no workaround, so this should be scheduled into the next patch cycle rather than treated as an emergency.

Why it matters:

  • The flaw sits in the web-based management interface of Unified CM and Unified CM SME, the systems that handle enterprise call routing and telephony administration.
  • Exploitation requires valid administrative credentials, which narrows exposure but means any compromised or malicious admin account can inject script that runs in other admins’ browser sessions.
  • No workaround exists, so exposure persists on unpatched 12.5 and 14 trains until they are migrated, and on 15 until 15SU3 is applied.
  • Successful exploitation can expose sensitive browser-based session information within the management console, which oversees voice infrastructure.

Now / Next / Later:

  • Now: Review who holds administrative access to Unified CM and Unified CM SME and tighten or revoke any accounts that are not actively needed.
  • Next: Upgrade Unified CM and Unified CM SME to 15SU3, or migrate 12.5 and 14 deployments onto a supported, fixed release, since no workaround is available.
  • Later: Apply stricter input validation review and least-privilege access controls to Unified CM’s admin interface as part of routine patch management, given no interim mitigation exists for issues like this.