Cisco Unified Communications Products Privilege Escalation Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 5.1 Security Advisory

TL;DR 📌

A privilege escalation vulnerability has been identified in multiple Cisco Unified Communications and Contact Center Solutions products. An authenticated local attacker could exploit this vulnerability to gain root access on affected devices. Cisco has released software updates to address this issue, but there are no workarounds available.

What happened 🕵️‍♂️

A vulnerability in various Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate their privileges to root on an affected device. This vulnerability arises from excessive permissions assigned to system commands, enabling an attacker to execute crafted commands on the underlying operating system. To exploit this vulnerability, administrative access to the ESXi hypervisor is required.

Affected products 🖥️

The following Cisco products are affected by this vulnerability:

  • Customer Collaboration Platform (CCP)
  • Emergency Responder
  • Finesse
  • Prime Collaboration Deployment
  • Unified Communications Manager (CM)
  • Unified Communications Manager IM & Presence Service (IM&P)
  • Unified Communications Manager Session Management Edition (CM SME)
  • Unified Contact Center Express (CCX)
  • Unified Intelligence Center
  • Unity Connection
  • Virtualized Voice Browser

For detailed information about specific bug IDs, please refer to the advisory.

Fixed software 🔧

Upgrade to at least the first fixed release in your train (or later):

Product / Release Train First Fixed Release Notes
ISE / ISE-PIC 14 Migrate to a fixed release.
ISE / ISE-PIC 15 15SU2
ISE / ISE-PIC 12 Migrate to a fixed release.
ISE / ISE-PIC 15 Not vulnerable.
ISE / ISE-PIC 1.0 Initial public release.

Workarounds 🧯

There are no workarounds available to mitigate this vulnerability.

Risk in context 🎯

The vulnerability has a CVSS score of 5.1, categorized as MEDIUM severity. While this indicates a moderate risk, the potential for an attacker to gain root access on affected devices underscores the importance of applying the recommended software updates promptly.

Fast facts ⚡

  • Advisory ID: cisco-sa-cucm-kkhZbHR5
  • CVSS Score: 5.1 (MEDIUM)
  • Vulnerability Type: Privilege Escalation
  • Exploitation Requirement: Administrative access to the ESXi hypervisor

For leadership 🧭

Executive summary. Anyone who already holds ESXi administrator access to your Cisco Unified Communications or Contact Center virtual appliances can escalate to root on the underlying operating system, giving full control of call control and contact centre platforms. There’s no workaround, so this should be scheduled into the next patch cycle rather than treated as an emergency given the required hypervisor-level access.

Why it matters:

  • Affects a wide range of collaboration infrastructure including Unified Communications Manager, Unity Connection, Finesse, Emergency Responder and Unified Contact Center Express, so a single flaw touches call routing, voicemail, and contact centre systems.
  • Excessive permissions on system commands mean the guest OS root boundary is only as strong as the ESXi hypervisor access controls around these VMs.
  • Root access on any of these appliances would let an attacker tamper with call detail records, voicemail, emergency routing, or contact centre queuing without further privilege barriers.
  • No mitigating configuration exists, so exposure persists until the affected VM’s software is upgraded.

Now / Next / Later:

  • Now: Review who holds ESXi administrator credentials for hosts running these Cisco Unified Communications and Contact Center virtual appliances, and tighten that access list immediately.
  • Next: Upgrade each affected product to its first fixed release identified in the advisory during the next scheduled maintenance window.
  • Later: Separate hypervisor administration duties from application administration for collaboration platforms, and require regular audits of who can reach the ESXi management plane hosting these VMs.