Cisco Unified Communications Products Command Injection Vulnerability
TL;DR 📌
A command injection vulnerability has been identified in multiple Cisco Unified Communications products. This flaw allows an authenticated local attacker to execute arbitrary commands on the underlying operating system as the root user. Cisco has released software updates to address this issue, and there are no workarounds available.
What happened 🕵️♂️
A vulnerability in the Command Line Interface (CLI) of several Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the affected device’s operating system as the root user. This vulnerability stems from improper validation of user-supplied command arguments. To exploit this vulnerability, the attacker must possess valid administrative credentials.
Affected products 🖥️
The following Cisco products are affected by this vulnerability if they are running a vulnerable software release:
- Customer Collaboration Platform (CCP)
- Finesse
- Unified Communications Manager (Unified CM)
- Unified Communications Manager IM & Presence Service (Unified CM IM&P)
- Unified Communications Manager Session Management Edition (Unified CM SME)
- Unified Contact Center Express (Unified CCX)
- Unified Intelligence Center
- Unity Connection
- Virtualized Voice Browser
Fixed software 🔧
Upgrade to at least the first fixed release in your train (or later):
| Product / Release Train | First Fixed Release | Notes |
|---|---|---|
| ISE / ISE-PIC 15.0 | 15.0(1) | |
| ISE / ISE-PIC 12.6 | 12.6(2)ES6 | |
| ISE / ISE-PIC 15.0 | 15SU2 | |
| ISE / ISE-PIC 12.6 | 12.6(2)ES04 | |
| ISE / ISE-PIC 12.6 | 12.6(2)ES06 | |
| ISE / ISE-PIC 1.0 | Initial public release. |
Workarounds 🧯
There are no workarounds available to mitigate this vulnerability.
Risk in context 🎯
The highest CVSS score for this vulnerability is 6.0, indicating a medium severity level. While the risk is notable, it requires authenticated access, which limits the potential for widespread exploitation. However, organizations using the affected products should prioritize applying the necessary updates to safeguard their systems.
Fast facts ⚡
- Vulnerability Type: Command Injection
- CVSS Score: 6.0 (Medium)
- Exploitation Requirements: Valid administrative credentials
- Affected Products: Multiple Cisco Unified Communications products
- Fixed Releases Available: Yes, for all affected products
For leadership 🧭
Executive summary. A CLI flaw in Cisco’s Unified Communications line, including Unified CM, Unity Connection and Finesse, lets someone with valid admin credentials escalate to root on the host OS. There’s no workaround, so this needs a patch cycle scheduled rather than emergency action, but it should not be left indefinitely given the breadth of affected voice and contact centre platforms.
Why it matters:
- Root access via the CLI on core telephony and contact centre systems (Unified CM, Unity Connection, Unified CCX and others) could let an admin-level attacker or compromised admin account fully take over the underlying host, not just the application.
- The flaw requires valid administrative credentials, so the main exposure is from insider misuse, credential theft, or compromised admin accounts rather than an anonymous network attacker.
- No workaround exists, so mitigation is limited to controlling who holds admin credentials until the fixed release is installed.
- The list of affected products spans nearly the entire Cisco Unified Communications portfolio, meaning a single credential compromise anywhere in that estate could lead to root-level access.
Now / Next / Later:
- Now: Identify every instance of the affected Unified Communications products in your estate and check which software train each is running against the fixed-release table.
- Next: Schedule upgrades to the first fixed release (or later) for each affected product during your next maintenance window, prioritising systems where admin CLI access is shared or loosely controlled.
- Later: Tighten and audit who holds administrative CLI credentials on Unified Communications platforms, since this class of flaw depends entirely on that access being available to an attacker.