A vulnerability in the Java Remote Management Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a malicious serialized Java object to a specific listener on an affected system. A successful exploit could allow the attacker to execute arbitrary code as the root user on an affected device.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 15 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: cisco
Published: 2020-05-22T05:15:42.288042Z
Updated: 2024-11-15T17:20:41.801Z
Reserved: 2019-12-12T00:00:00
Link: CVE-2020-3280
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-04T07:30:57.525Z
 NVD
                        NVD
                    Status : Modified
Published: 2020-05-22T06:15:10.430
Modified: 2024-11-21T05:30:42.907
Link: CVE-2020-3280
 Redhat
                        Redhat
                    No data.