Hi Cisco Security Team,
I'm reaching out to inform you about a publicly disclosed vulnerability affecting Cisco CUCM that may be relevant to your security awareness efforts.
Vulnerability: Cisco CUCM Remote Code Execution Chain (CVSS 9.8 Critical)
Disclosure Project: 0day Rubbish
Repository: https://github.com/Exploit-Garbage/0day-Rubbish
Specific Disclosure: https://github.com/Exploit-Garbage/0day-Rubbish/tree/main/product/cisco/cucm-14.0/rce-chain
Overview:
An independent security research project has publicly disclosed a critical RCE chain affecting Cisco Unified Communications Manager (CUCM) 14.0 and earlier versions. The vulnerability chain includes:
- SQL Injection (blind, DNS exfiltration)
- XML External Entity (XXE) injection
- AES-CBC decryption exploitation
- Apache Axis service deployment
- Freemarker template engine RCE
- Root-level command execution
Key Details:
- CVSS Score: 9.8 (Critical)
- Affected Versions: CUCM 14.0 and earlier
- Working PoC exploit code included in disclosure
- Complete technical analysis with attack chain documentation
Purpose of This Issue:
This is an informational notice to ensure Cisco security teams are aware of this public disclosure. The full technical details, exploit code, and mitigation recommendations are available in the linked repository.
We believe transparent vulnerability disclosure helps strengthen overall ecosystem security.
Best regards,
0day Rubbish Team
Hi Cisco Security Team,
I'm reaching out to inform you about a publicly disclosed vulnerability affecting Cisco CUCM that may be relevant to your security awareness efforts.
Vulnerability: Cisco CUCM Remote Code Execution Chain (CVSS 9.8 Critical)
Disclosure Project: 0day Rubbish
Repository: https://github.com/Exploit-Garbage/0day-Rubbish
Specific Disclosure: https://github.com/Exploit-Garbage/0day-Rubbish/tree/main/product/cisco/cucm-14.0/rce-chain
Overview:
An independent security research project has publicly disclosed a critical RCE chain affecting Cisco Unified Communications Manager (CUCM) 14.0 and earlier versions. The vulnerability chain includes:
Key Details:
Purpose of This Issue:
This is an informational notice to ensure Cisco security teams are aware of this public disclosure. The full technical details, exploit code, and mitigation recommendations are available in the linked repository.
We believe transparent vulnerability disclosure helps strengthen overall ecosystem security.
Best regards,
0day Rubbish Team