CVE-2023-20232
Last modified
CVE-2023-20232 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A vulnerability in the Tomcat implementation for Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to cause a web cache poisoning attack on an affected device. This vulnerability is due to improper input validation of HTTP requests. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
A vulnerability in the Tomcat implementation for Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to cause a web cache poisoning attack on an affected device. This vulnerability is due to improper input validation of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a specific API endpoint on the Unified CCX Finesse Portal. A successful exploit could allow the attacker to cause the internal WebProxy to redirect users to an attacker-controlled host.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Contact Center Express | < 12.5\(1\)_su2_es05 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-20232?
How severe is CVE-2023-20232?
How do I fix CVE-2023-20232?
Are you affected by CVE-2023-20232?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
