VDB

CVE-2022-20859

CVE-2022-20859 PUBLISHED CVSS 6.5 MEDIUM

A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authenticated, remote attacker to perform certain administrative actions they should not be able to. This vulnerability is due to insufficient access control checks on the affected device. An attacker with read-only privileges could exploit this vulnerability by executing a specific vulnerable command on an affected device. A successful exploit could allow the attacker to perform a set of administrative actions they should not be able to.

EPSS 1.64% · 82.3th percentile

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS Score
1.64%
82.3th percentile

Affected Products

VendorProductVersions
ciscounified_communications_manager_im_and_presence_service14.0
ciscounity_connection14.0
ciscounified_communications_manager14.0
CiscoCisco Unified Communications Manager*

Timeline

  • Jul 6, 2022 CVE Published
  • Jul 7, 2022 EPSS Score
  • Aug 24, 2022 EPSS Score
  • Oct 11, 2022 EPSS Score
  • Jan 13, 2023 EPSS Score
  • Mar 2, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 18, 2023 EPSS Score
  • Jun 4, 2023 EPSS Score
  • Jul 21, 2023 EPSS Score
  • Oct 24, 2023 EPSS Score
  • Dec 10, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›