CVE-2019-15272

MEDIUM

Cisco Unified Communications Manager - HTTP Request Smuggling

Title source: rule
STIX 2.1

Description

A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to bypass security restrictions. The vulnerability is due to improper handling of malformed HTTP methods. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected system. A successful exploit could allow the attacker to gain unauthorized access to the system.

Scores

CVSS v3 6.5
EPSS 0.0007
EPSS Percentile 22.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-444 CWE-264
Status published
Products (4)
cisco/unified_communications_manager 10.5\(2.10000.5\)
cisco/unified_communications_manager 11.5\(1.10000.6\)
cisco/unified_communications_manager 12.0\(1.10000.10\)
cisco/unified_communications_manager 12.5\(1.10000.22\)
Published Oct 02, 2019
Tracked Since Feb 18, 2026