Cisco Unified Intelligent Contact Management Enterprise Cross-Site Scripting Vulnerability
TL;DR 📌
A cross-site scripting (XSS) vulnerability has been identified in the web-based management interface of Cisco Unified Intelligent Contact Management Enterprise. This could allow an unauthenticated attacker to execute arbitrary script code. No workarounds are available, and software updates are forthcoming.
What happened 🕵️♂️
Cisco has disclosed a vulnerability in the web-based management interface of Cisco Unified Intelligent Contact Management Enterprise. This vulnerability arises from insufficient user input validation, enabling an attacker to potentially execute arbitrary script code within the context of the affected interface. The attacker would need to persuade a user to click on a crafted link to exploit this vulnerability.
Affected products 🖥️
At the time of publication, the vulnerability affects:
- Cisco Unified Intelligent Contact Management Enterprise 15.0(1) and earlier.
For the most current information, refer to the details section in the bug ID(s) at the top of the advisory.
Fixed software 🔧
Upgrade to at least the first fixed release in your train (or later):
| Product / Release Train | First Fixed Release | Notes |
|---|---|---|
| ISE / ISE-PIC 1.0 | Initial public release. |
Workarounds 🧯
There are no workarounds available to mitigate this vulnerability.
Risk in context 🎯
The vulnerability has a CVSS score of 6.1, categorized as MEDIUM severity. While this does not indicate an immediate critical threat, it is essential for users of the affected products to remain vigilant and apply updates as soon as they are available to prevent potential exploitation.
Fast facts ⚡
- Vulnerability Type: Cross-Site Scripting (XSS)
- CVSS Score: 6.1 (Medium)
- Affected Product: Cisco Unified Intelligent Contact Management Enterprise 15.0(1) and earlier
- Workarounds: None available
- Status: Final advisory with planned software updates
For leadership 🧭
Executive summary. Contact centre supervisors and admins using the Unified ICM Enterprise web interface could be tricked into clicking a malicious link that runs attacker script in their session. There’s no fix deployed yet and no workaround, so this needs tracking for the update rather than emergency action tonight.
Why it matters:
- The flaw sits in the web-based management interface of Unified ICM Enterprise, a component used to administer contact centre routing and configuration.
- Exploitation requires no authentication from the attacker but relies on a user with interface access clicking a crafted link, making phishing-style delivery the likely path.
- Affected versions run up to and including 15.0(1), so any contact centre still on that release or earlier is exposed.
- No workaround exists, meaning the only mitigation until a patch ships is reducing exposure of the interface and user awareness.
Now / Next / Later:
- Now: Identify all Unified ICM Enterprise deployments on 15.0(1) or earlier and restrict who can reach the web management interface, particularly from general user networks.
- Next: Brief administrators and supervisors who use the ICM Enterprise web interface on the risk of clicking unsolicited links, and monitor for the Cisco fixed release to schedule an upgrade.
- Later: Add Unified ICM Enterprise to routine patch tracking against Cisco security advisories and review admin interface exposure as a standing control, not a one-off check.