漏洞描述 Cisco Unity Connection(UC)是美国思科(Cisco)公司的一套语音留言平台。该平台可利用语音命令,以免提方式拨打电话或收听留言。 Cisco Unity Connection 存在安全漏洞,该漏洞源于基于 Web 的管理界面中存在漏洞,可能允许未经身份验证的远程攻击者将任意文件上传到受影响的系统并在底层操作系统上执行命令。
相关漏洞推荐 (CVE-2025-62712) JumpServer ConnectionToken 权限验证不当漏洞 (CVE-2025-36604)Dell Unity OS命令注入漏洞 Cisco Secure Firewall Management Center和Cisco Secure Firewall Threat Defense 操作系统命令注入漏洞 POC CVE-2001-0537: Cisco IOS HTTP Configuration - Authentication Bypass POC CVE-2009-1558: Cisco Linksys WVC54GCA 1.00R22/1.00R24 - Local File Inclusion POC CVE-2011-3315: Cisco CUCM, UCCX, and Unified IP-IVR- Directory Traversal POC CVE-2013-5528: Cisco Unified Communications Manager 7/8/9 - Directory Traversal POC CVE-2018-0127: Cisco RV132W/RV134W Router - Information Disclosure POC CVE-2018-0296: Cisco ASA - Local File Inclusion POC CVE-2019-1653: Cisco Small Business WAN VPN Routers - Sensitive Information Disclosure POC CVE-2019-1821: Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager - Remote Code Execution POC CVE-2019-1898: Cisco RV110W RV130W RV215W Router - Information leakage POC CVE-2019-1943: Cisco Small Business 200,300 and 500 Series Switches - Open Redirect