CVE-2026-20034
CVSS 8.8 HIGH: a vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote…
Vulnerabilità · 145 giorni fa
L’ultimo advisory di Cisco amplia il raggio d’impatto oltre una singola linea di prodotto. I nuovi problemi trasformano Unity Connection in un punto di esecuzione a livello root e in un pivot SSRF, e consentono al traffico SNMP malformato di riavviare gli switch SG350 e SG350X, quindi il rischio reale è la compromissione del management plane e l’interruzione del servizio, non solo un altro bug ad alta gravità.
CVSS 8.8 HIGH: a vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote…
CVSS 7.2 HIGH: a vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to…
3 fonti che coprono questa storia
Cisco Patches High-Severity Vulnerabilities in Enterprise Products
Successful exploitation of the flaws could lead to code execution, server-side request forgery attacks, and denial-of-service conditions.
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco 350 Series Managed Switches (SG350) and Cisco 350X Series Stackable Managed Switches (SG350X) firmware could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
Multiple vulnerabilities in Cisco Unity Connection could allow a remote attacker to execute arbitrary code on or conduct server-side request forgery (SSRF) attacks through an affected device.
A vulnerability in the connection-handling mechanism of Cisco Crosswork Network Controller (CNC) and Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected system.
Cisco Security Advisory: Cisco IoT Field Network Director Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco IoT Field Network Director Software could allow an authenticated, remote attacker to access files, execute commands, and cause denial of service (DoS) conditions on managed routers.
New Cisco DoS flaw requires manual reboot to revive devices
Cisco patched a Crosswork Network Controller and Network Services Orchestrator denial-of-service vulnerability that requires manually rebooting targeted systems for recovery.
Part of the PlainSec briefing for 2026-05-06