CVE-2023-20116
MEDIUMCisco Unified Communications Manager - Authenticated Denial of Service via AXL API Input Validation
Title source: llmDescription
A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the web UI of the Self Care Portal. An attacker could exploit this vulnerability by sending crafted HTTP input to an affected device. A successful exploit could allow the attacker to cause a DoS condition on the affected device.
References (1)
Core 1
Core References
Scores
CVSS v3
6.8
EPSS
0.0060
EPSS Percentile
44.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H
Details
CWE
CWE-835
Status
published
Products (4)
cisco/unified_communications_manager
11.5\(1.10000.6\) (2 CPE variants)
cisco/unified_communications_manager
12.0\(1.10000.10\) (2 CPE variants)
cisco/unified_communications_manager
12.5\(1.10000.22\) (2 CPE variants)
cisco/unified_communications_manager
14.0\(1.10000.20\) (2 CPE variants)
Published
Jun 28, 2023
Tracked Since
Feb 18, 2026