CVE-2023-20062
03.03.2023, 16:15
Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these vulnerabilities.
Vendor | Product | Version |
---|---|---|
cisco | packaged_contact_center_enterprise | - |
cisco | unified_contact_center_enterprise | - |
cisco | unified_contact_center_express | - |
cisco | unified_intelligence_center | 𝑥 < 12.6\(2\) |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-918 - Server-Side Request Forgery (SSRF)The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.