← Back to CVE List
Vulnerability Intelligence Report

CVE-2023-20259

A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to cause high CPU utilization, which could impact access to the web-based management interface and cause delays with call processing. This API is not used for device management and is unlikely to be used in normal operations of the device. This vulnerability is due to improper API authentication and incomplete validation of the API request. An attacker could exploit this vulnerability by sending a crafted HTTP request to a specific API on the device. A successful exploit could allow the attacker to cause a denial of service (DoS) condition due to high CPU utilization, which could negatively impact user traffic and management access. When the attack stops, the device will recover without manual intervention.

No Active Exploit Signals
CVSS Base Score
8.6
HIGH
Exploitability:3.9
Impact Score:4.0
EPSS Probability:0.61%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-400 ↗Uncontrolled Resource Consumption

Affected Products & Versions

Vendor Product Affected Versions
Cisco Cisco Emergency Responder 12.5(1)SU7 (affected), 14 (affected), 14SU3 (affected)
Cisco Cisco Unity Connection 14SU3 (affected)
Cisco Cisco Unified Communications Manager 12.5(1)SU7 (affected), 12.5(1)SU7a (affected), 14SU3 (affected)
Cisco Cisco Unified Communications Manager IM and Presence Service 12.5(1)SU7 (affected), 14SU3 (affected)
Cisco Cisco Prime Collaboration Deployment 14SU3 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.612%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCisco Systems, Inc. · Hosted Service · USA
Reserved2022-10-27T18:47:50
Published2023-10-04T16:13:30
Last Updated2024-08-02T09:05:36

LINK COPIED TO CLIPBOARD