CVE-2023-20259 is a denial-of-service vulnerability affecting multiple Cisco Unified Communications Products, including Emergency Responder and Unified Communications Manager. An unauthenticated, remote attacker can exploit this flaw by sending crafted HTTP requests to a specific API endpoint, leading to high CPU utilization and impacting management access and call processing. Rated 7.5 High on CVSS, the attack is network-based and low complexity, causing a denial of service without requiring user interaction. While there are no known public exploits or active exploitation, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
14su3CPE matchmatch criteria | cpe:2.3:a:cisco:emergency_responder:14su3:*:*:*:*:*:*:* | ||
14su3CPE matchmatch criteria | cpe:2.3:a:cisco:prime_collaboration_deployment:14su3:*:*:*:*:*:*:* | ||
12.5\(1\)su7CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:12.5\(1\)su7:*:*:*:*:*:*:* | ||
12.5\(1\)su7CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:12.5\(1\)su7:*:*:*:session_management:*:*:* | ||
14su3CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:14su3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.