CVE-2022-20816

MEDIUM

Cisco Unified Communications Manager 11.5(1)-14su2 - Authenticated Arbitrary File Deletion via HTTP Request

Title source: llm
STIX 2.1

Description

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to delete arbitrary files from an affected system. This vulnerability exists because the affected software does not properly validate HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow the attacker to delete arbitrary files from the affected system.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0071
EPSS Percentile 72.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
cisco/unified_communications_manager 11.5\(1\) - 14su2 (2 CPE variants)
Published Aug 10, 2022
Tracked Since Feb 18, 2026