SB2017062308 - Authentication bypass in Cisco Unified Contact Center Express



SB2017062308 - Authentication bypass in Cisco Unified Contact Center Express

Published: June 23, 2017

Security Bulletin ID SB2017062308
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Authentication bypass (CVE-ID: CVE-2017-6722)

The vulnerability allows a remote unauthenticated attacker to bypass authentication.

The weakness exists in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) due to the XMPP service incorrectly processing an unsecured HTTP port for third-party, remote presence monitoring. A remote attacker can gain unauthorized access to the system.

Remediation

Install update from vendor's website.