Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Cholayil Private Limited

Cholayil Private Limited Vendor Cyber Rating & Cyber Score

cholayil.com

Cholayil Pvt Ltd (CPL) is one of the leading and fastest growing companies in India having a strong presence in the FMCG industry. The company, rooted in tradition but modern in its thought and approach, is a pioneer in the field of Ayurveda and natural personal care products. CPL introduced the flagship brand ‘Medimix’ in 1969 which was followed by acquiring ‘Cuticura’ and ‘Krishna Thulasi’ brands in 2001 and 2011 respectively. It has implemented several strategic initiatives to become a dominant player with strong brand equity in the personal care industry. Cholayil Pvt. Ltd. is also the parent company of Dr. Sidhan’s Ayur Mix, Sadayush, Sadhev and Jullaaha brands. Today CPL has basket of brands which are popular not only in India but


CPL A.I CyberSecurity Scoring

CPL
Company Information
Website:http://www.cholayil.com
Employees number:517
Number of followers:35,162
NAICS:32562
Industry Type:Personal Care Product Manufacturing
Homepage:cholayil.com
CPL Risk Score (AI oriented)
Between 750 and 799
logo
CPLPersonal Care Product Manufacturing
Updated:
13/03/2026
756/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
CPL Global Score (TPRM)
xxxx
logo
CPLPersonal Care Product Manufacturing
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

CPL
CPLFair
Current Score
756Baa (FAIR)
01000
1 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
756Before Incident
Vulnerability
04 Jun 2026CPL
Cisco: PoC Exploit Released for Cisco Unified Communications Manager Security Vulnerability

Critical SSRF Vulnerability in Cisco Unified CM Exploited via Public PoC

753After Incident
CRITICAL-3
CIS1780568638
Critical SSRF Vulnerability in Cisco Unified CM Exploited via Public PoC A proof-of-concept (PoC) exploit has been released for a critical server-side request forgery (SSRF) vulnerability in Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (Unified CM SME), tracked as CVE-2026-20230. The flaw, rated 8.6 (High) on the CVSS v3.1 scale but classified as Critical by Cisco due to its potential for root-level privilege escalation, exposes vulnerable systems to remote exploitation. The vulnerability arises from improper input validation in HTTP requests (CWE-918), allowing unauthenticated attackers to interact with internal services. By sending crafted HTTP requests, threat actors can perform SSRF attacks and write arbitrary files to the underlying OS, enabling privilege escalation and potential full system compromise. Exploitation is only possible if the Cisco WebDialer service disabled by default but active in some deployments is enabled. The public release of the PoC exploit heightens the risk, as it provides attackers with a functional attack method. Security researchers confirm the exploit demonstrates SSRF-based file-writing capabilities, which could be used for persistence or further lateral movement, particularly in internet-facing or compromised internal networks. Affected systems include Cisco Unified CM and Unified CM SME with the WebDialer service running. Administrators can check vulnerability status via the Cisco Unified CM Administration interface under Cisco Unified Serviceability > Control Center – Feature Services. If the Cisco WebDialer Web Service is marked as "Started," the system is exposed. Cisco has released software updates to patch the flaw, with no official workarounds available. As a temporary mitigation, disabling the WebDialer service is recommended. Additional defensive measures include restricting access to management interfaces and monitoring for suspicious outbound HTTP requests or unauthorized file creation. While no active compromises have been reported, organizations are urged to prioritize patching due to the high risk of exploitation and the potential for root-level access. The vulnerability underscores the urgency of securing enterprise communication systems against SSRF-based attacks.
INCIDENT DETAILS -
TYPE
SSRF (Server-Side Request Forgery)
IMPACT
Systems Affected: Cisco Unified CM and Unified CM SME with WebDialer service enabledOperational Impact: Potential full system compromise, root-level privilege escalation
MAY 2026
756Before Incident
APRIL 2026
756Before Incident
MARCH 2026
756Before Incident
FEBRUARY 2026
756Before Incident
JANUARY 2026
756Before Incident
DECEMBER 2025
756Before Incident
NOVEMBER 2025
756Before Incident
OCTOBER 2025
756Before Incident
SEPTEMBER 2025
756Before Incident
AUGUST 2025
756Before Incident
JULY 2025
756Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for CPL ?
?
What was CPL's A.I Rankiteo Cyber Score in May 2026 ?
?
What was CPL's A.I Rankiteo Cyber Score in April 2026 ?
?
What was CPL's A.I Rankiteo Cyber Score in March 2026 ?
?
What was CPL's A.I Rankiteo Cyber Score in February 2026 ?
?
What was CPL's A.I Rankiteo Cyber Score in January 2026 ?
?
What was CPL's A.I Rankiteo Cyber Score in December 2025 ?
?
What was CPL's A.I Rankiteo Cyber Score in November 2025 ?
?
What was CPL's A.I Rankiteo Cyber Score in October 2025 ?
?
What was CPL's A.I Rankiteo Cyber Score in September 2025 ?
?
What was CPL's A.I Rankiteo Cyber Score in August 2025 ?
?
What was CPL's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on CPL's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with CPL ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view CPL's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?