Cisco has released free software updates that address the vulnerability described in this advisory. Customers may only install and expect support for software versions and feature sets for which they have purchased a license. By installing, downloading, accessing, or otherwise using such software upgrades, customers agree to follow the terms of the Cisco software license:
Additionally, customers may only download software for which they have a valid license, procured from Cisco directly, or through a Cisco authorized reseller or partner. In most cases this will be a maintenance upgrade to software that was previously purchased. Free security software updates do not entitle customers to a new software license, additional software feature sets, or major revision upgrades.
When considering software upgrades, customers are advised to regularly consult the advisories for Cisco products, which are available from the Cisco Security Advisories and Alerts page, to determine exposure and a complete upgrade solution.
In all cases, customers should ensure that the devices to be upgraded contain sufficient memory and confirm that current hardware and software configurations will continue to be supported properly by the new release. If the information is not clear, customers are advised to contact the Cisco Technical Assistance Center (TAC) or their contracted maintenance providers.
Customers Without Service Contracts
Customers who purchase directly from Cisco but do not hold a Cisco service contract and customers who make purchases through third-party vendors but are unsuccessful in obtaining fixed software through their point of sale should obtain upgrades by contacting the Cisco TAC:
Customers should have the product serial number available and be prepared to provide the URL of this advisory as evidence of entitlement to a free upgrade.
This vulnerability is fixed in Cisco Prime License Manager patch ciscocm.CSCvk30822_v2.0.k3.cop.sgn (the v1.0 release of this patch should no longer be used due to functional issues caused by that version of the patch). The same COP file can be used with standalone deployments of Cisco Prime License Manager as well as with coresident deployments as part of Cisco Unified Communications Manager and Cisco Unity Connection and with all affected versions. Installation instructions are available in a corresponding Readme document.
Note: This patch can be installed on Cisco Prime License Manager, Cisco Unified Communications Manager, and Cisco Unity Connection 11.5(1) only. Customers running an earlier release will need to upgrade to 11.5(1) prior to installing this patch.
Functional Issues Identified in the v1.0 Patch File
Installing the ciscocm.CSCvk30822_v1.0.k3.cop.sgn patch on standalone or coresident PLM will resolve the vulnerability described in this advisory, but this action will disable the following features:
- Install/upgrade functionality in the PLM GUI
- Backup and Restore functionality in the PLM GUI
Workarounds for the Functional Issues
- Install/upgrade can be accomplished by using the CLI.
- There is no workaround for the Backup and Restore functionality.
- Install/upgrade can be accomplished by using the CUCM/CUC GUI.
- Backup and Restore functionality continues to be available in the CUCM/CUC GUI.
Upgrading from the v1.0 Patch to the v2.0 Patch
Customers who have previously installed the ciscocm.CSCvk30822_v1.0.k3.cop.sgn patch should upgrade to the ciscocm.CSCvk30822_v2.0.k3.cop.sgn patch to remediate the functional issues. Installing the v2.0 patch will first rollback the v1.0 patch and then install the v2.0 patch:
- Download the ciscocm.CSCvk30822_v2.0.k3.cop.sgn file from the locations indicated in the Patch and Patch Rollback File Download section of this advisory.
- Install that downloaded file by using the CLI (for a standalone PLM) or by using the CUCM/CUC GUI (for a coresident PLM).
Patch and Patch Rollback File Download
The patch files and patch rollback files, including a Readme document, are available for download from the Software Center on Cisco.com by navigating to the following locations:
Cisco Prime License Manager
Browse all > Cloud and Systems Management > Collaboration and Unified
Communications Management > Prime License Manager > Prime License
Manager 11.5 > Prime License Manager Software Patches > UTILS
Cisco Unified Communications Manager
Browse all > Unified Communications > Call Control > Unified Communications Manager (CallManager) > Unified Communications Manager Version 11.5 > Unified Communications Manager / CallManager / Cisco Unity Connection Utilities > COP-Files
Cisco Unity Connection
Browse all > Unified Communications > Unified Communications Applications > Messaging > Unity Connection > Unity Connection Version 11.x > Unified Communications Manager / CallManager / Cisco Unity Connection Utilities > COP-Files