SB2017062308 - Authentication bypass in Cisco Unified Contact Center Express
Published: June 23, 2017
Security Bulletin ID
SB2017062308
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Authentication bypass (CVE-ID: CVE-2017-6722)
The vulnerability allows a remote unauthenticated attacker to bypass authentication.The weakness exists in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) due to the XMPP service incorrectly processing an unsecured HTTP port for third-party, remote presence monitoring. A remote attacker can gain unauthorized access to the system.
Remediation
Install update from vendor's website.