CYBER CODE RED

Get real-time updates on Telegram

P3Verified

CVE-2026-20230: unified communications manager from 14.0 (inclusive), before 14su6 (exclusive), from 15.0 (inclusive), through 15su4a…

CVE-2026-20230. CVSS 3.1 base score 8.6 (HIGH, Vendor/CNA). EPSS 0.882 (percentile 0.99766), scored 2026-10-06.

Affected technology

unified communications manager · from 14.0 (inclusive), before 14su6 (exclusive)
cisco

unified communications manager · from 15.0 (inclusive), through 15su4a (inclusive)
cisco

Cisco Unified Communications Manager · 14, 14SU1, 14SU2, 14SU3, 15, 15SU1, 14SU4, 14SU4a, 15SU1a, 15SU2, 15.0.1.13010-1, 15.0.1.13011-1, 15.0.1.13012-1, 15.0.1.13013-1, 15.0.1.13014-1, 15.0.1.13015-1, 15.0.1.13016-1, 15.0.1.13017-1, 15SU3a, 14SU5, 15SU4, 15SU4a
Cisco

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

An unauthenticated, remote attacker could conduct server-side request forgery (SSRF) attacks through an affected device. Vendor/CNA’s CVSS 3.1 assessment (base score 8.6/10) rates confidentiality and availability impact as none; integrity impact as high.

Published

CWE
CWE-918
CCR priority
56.5 /100 (P3)
CVSS 3.1
8.6 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N · Vendor/CNA
EPSS
0.882 · percentile 0.99766 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-20230.html