Cisco Unified Contact Center Enterprise Cloud Connect Insufficient Access Control Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 6.5 Security Advisory

TL;DR 📌

A medium-severity vulnerability has been identified in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE). This flaw could allow unauthenticated, remote attackers to read and modify data on affected devices. Cisco has released software updates to address this issue, but there are no workarounds available.

What happened 🕵️‍♂️

A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) has been discovered. This issue arises from insufficient access controls, enabling unauthenticated remote attackers to send crafted TCP data to a specific port on affected devices. If successfully exploited, attackers could read or modify data on these devices.

Affected products 🖥️

At the time of publication, the vulnerability affects Cisco Unified CCE Cloud Connect, regardless of device configuration. Specific software releases that were vulnerable include:

  • Cisco Unified CCE Cloud Connect Release 12.6.2 (requires migration to a fixed release)
  • Cisco Unified CCE Cloud Connect Release 12.6.1 and earlier (not vulnerable)
  • Cisco Unified CCE Cloud Connect Release 15.0.1 (not vulnerable)

Fixed software 🔧

Upgrade to at least the first fixed release in your train (or later):

Product / Release Train First Fixed Release Notes
ISE / ISE-PIC 1.0 Initial public release.

Workarounds 🧯

There are no workarounds available to mitigate this vulnerability.

Risk in context 🎯

With a CVSS score of 6.5, this vulnerability is classified as medium severity. The potential for unauthorized data access and modification poses a significant risk to organizations using affected Cisco Unified CCE Cloud Connect systems. Immediate action is recommended to upgrade to a fixed release.

Fast facts ⚡

  • Advisory ID: cisco-sa-contcent-insuffacces-ArDOVhN8
  • CVSS Score: 6.5 (Medium)
  • Vulnerability Type: Insufficient Access Control
  • Exploitation: Unauthenticated remote attackers can exploit this vulnerability.

For leadership 🧭

Executive summary. Contact centre systems running the Cloud Connect component on Cisco Unified CCE 12.6.2 can have their data read or changed by a remote attacker who never needs to log in. There is no workaround, so the fix depends entirely on scheduling the upgrade, and it should be treated as a priority change rather than routine maintenance.

Why it matters:

  • The flaw sits in the Cloud Connect component of Cisco Unified Contact Center Enterprise, which handles cloud integration for contact centre deployments – a component many teams may not think to check separately from the core CCE platform.
  • No authentication is required; an attacker only needs to reach the affected TCP port to read or modify data on the device.
  • Cisco has confirmed no workaround exists, so mitigation is limited to network-level access restriction until the fixed release is applied.
  • Only Cloud Connect Release 12.6.2 is confirmed vulnerable, with 12.6.1 and earlier, and 15.0.1, unaffected – so exposure depends on which specific release each Cloud Connect node is running.

Now / Next / Later:

  • Now: Identify every Cloud Connect node in your Unified CCE estate and check whether it is running Release 12.6.2; if so, restrict network access to the relevant TCP port as an interim measure.
  • Next: Schedule and apply the Cisco-provided upgrade to a fixed Cloud Connect release for all 12.6.2 systems in the next available change window, since no workaround is offered.
  • Later: Add Cloud Connect version tracking to your regular Cisco CCE patch review cycle so future releases affecting this component are caught before they reach production.