Cisco Unified Communications Manager XML External Expansion Vulnerability (cisco-sa-20191002-cucm-xxe)

medium Nessus Plugin ID 135897

Synopsis

The remote device is missing a vendor-supplied security patch

Description

According to its self-reported version, Cisco Unified Communications Manager is affected by an XML external entity (XXE) vulnerability. This is due to an incorrectly configured XML parser accepting XML external entities from an untrusted source. An unauthenticated, remote attacker can exploit this, via specially crafted XML data, to disclose sensitive information, or cause the application to consume available resources which would result in Denial of Service.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug ID CSCvp46079

See Also

http://www.nessus.org/u?421420ec

http://www.nessus.org/u?389f5230

Plugin Details

Severity: Medium

ID: 135897

File Name: cisco-sa-20191002-cucm-xxe.nasl

Version: 1.10

Type: combined

Family: CISCO

Published: 4/22/2020

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.5

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:P

CVSS Score Source: CVE-2019-12711

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:cisco:unified_communications_manager

Required KB Items: Host/Cisco/CUCM/Version, Host/Cisco/CUCM/Version_Display

Exploit Ease: No known exploits are available

Patch Publication Date: 10/2/2019

Vulnerability Publication Date: 10/2/2019

Reference Information

CVE: CVE-2019-12711

CWE: 611

CISCO-SA: cisco-sa-20191002-cucm-xxe

IAVA: 2019-A-0362

CISCO-BUG-ID: CSCvp46079