
As Cisco warned , organizations using the Unified Contact Center Express (Unified CCX) call center platform should update it immediately.
The company has released updates for its Unified CCX platform to fix a critical vulnerability in the Java -based remote management interface that could allow a remote attacker to install malware on the device without requiring credentials .
Cisco describes Unified CCX as a “contact center in a box, providing a secure and easy customer interaction management solution for up to 400 agents.”
A security expert found that this vulnerability could compromise Unified CCX systems by sending a malicious Java serial object to the remote management interface.
Cisco says the bug does not affect the larger Cisco Unified Contact Center, which supports contact centers with up to 24,000 agents.
To address the vulnerability, Cisco is urging customers using major versions of Unified CCX prior to 12.0, as well as 12.0 itself, to upgrade to version 12.0(1) ES03. Unified CCX 12.5 is not vulnerable.
The vulnerability is called CVE-2020-3280 and has a CVSS score of 9.8 out of 10 in terms of criticality.
However, Cisco's Product Security Incident Response Team (PSIRT) said it has not discovered any attacks that have exploited this vulnerability.
Cisco also released updates to fix a high-severity denial of service vulnerability affecting the Cisco Prime Network Registrar DHCP server .
There are also two other medium severity flaws that were recently patched, including an SQL injection that affects the web-based management interface of Cisco Prime Collaboration Provisioning Software and a denial of service flaw that affects the file scanning process of Cisco AMP for Endpoints Mac Connector Software.
