A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative permissions pertaining to script creation and execution. This vulnerability is due to improper authentication mechanisms in the communication between the CCX Editor and an affected Unified CCX server. An attacker could exploit this vulnerability by redirecting the authentication flow to a malicious server and tricking the CCX Editor into believing the authentication was successful. A successful exploit could allow the attacker to create and execute arbitrary scripts on the underlying operating system of an affected Unified CCX server, as an internal non-root user account.
The vulnerability stems from improper implementation of authentication mechanisms in the communication between the CCX Editor application and the Unified CCX server. An attacker can redirect the authentication flow to a malicious server, causing the CCX Editor application to incorrectly validate the login process. As a result, the attacker gains administrative privileges for creating and running scripts, which in turn allows execution of arbitrary code on the Unified CCX server operating system in the context of an internal user account without root privileges.
An attacker can create and execute arbitrary scripts on the Unified CCX server operating system, acting in the context of an internal user account (non-root). This results in unauthorized access to data, the ability to modify configuration, and potential takeover of the contact center environment.
Apply patches available from the vendor according to references published at: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cc-unauth-rce-QeN8h7mQ
Cisco Unified Contact Center Express — versions indicated in the vendor's references (Cisco advisory: cisco-sa-cc-unauth-rce-QeN8h7mQ)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:LCisco Unified Contact Center Express
APPCisco15.0< 12.5\(1\)_su03_es07
Related vulnerabilities
RCE z uprawnieniami root w Cisco Unified Contact Center Express (Java RMI)
RCE w produktach Cisco Unified Communications — eskalacja do root
Cisco Unified CCMP/CCDM — privilege escalation do roli Administrator
RCE poprzez insecure deserialization w Cisco Unified Contact Center Express
Cisco Unified CCX — ujawnienie hasła w postaci jawnego tekstu przez interfejs webowy