An attacker with ESXi hypervisor admin rights can escalate from the restricted shell of several Cisco Unified Communications and Contact Center virtual appliances straight to root on the guest OS.
Posts tagged: Cisco
Cisco Unified Contact Center Enterprise Cloud Connect Insufficient Access Control
Cisco’s Cloud Connect component in Unified Contact Center Enterprise accepts crafted TCP data on a specific port with no authentication check, letting a remote attacker read or alter data on the device.
Cisco Unified Intelligence Center Privilege Escalation Vulnerabilities
Two flaws in Cisco Unified Intelligence Center let anyone already logged in with a low-privilege account reach reporting data and functions meant for other roles, affecting every contact-centre product that bundles the tool.
Cisco Unified Intelligent Contact Management Enterprise Cross-Site Scripting
A stored input-validation flaw in Cisco ICM Enterprise’s web management interface lets an attacker run script in an administrator’s browser session if tricked into clicking a crafted link.
Cisco Webex Meetings Services HTTP Cache Poisoning Vulnerability
An unauthenticated attacker could poison cached HTTP responses in Cisco Webex Meetings’ cloud-based join service, causing some clients to receive incorrect responses when connecting to a meeting.
Cisco Webex Services Cross-Site Scripting Vulnerabilities
Three flaws in Cisco’s cloud-based Webex service let a crafted link inject scripting into a user’s session, with the fix applied server-side and no local patching needed.
Cisco ThousandEyes Endpoint Agent for Windows Arbitrary File Delete Vulnerabilities
A symbolic-link trick during agent upgrades lets a logged-in local user on Windows redirect the update process’s delete operation onto any protected file on the machine.
Cisco Unified Contact Center Express Editor Remote Code Execution Vulnerability
Opening a booby-trapped .aef script file in Cisco’s Unified CCX Editor can let an attacker run their own code on the machine, using whatever access the person who opened the file already has.
Cisco Unified Contact Center Express Vulnerabilities
Three separate flaws in the Cisco Unified CCX admin web interface let an already-authenticated administrator plant a stored XSS payload, deserialise a malicious Java object for code execution, or use path traversal plus SSH to run commands as root.
Cisco Integrated Management Controller Privilege Escalation Vulnerability
An authenticated attacker with SSH access to Cisco IMC on UCS B, C, S and X-Series servers can use crafted SSH syntax to reach internal services with elevated rights, up to creating new admin accounts.