First published: Thu Jan 26 2017(Updated: )
A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCvc20679. Known Affected Releases: 12.0(0.99000.9). Known Fixed Releases: 12.0(0.98000.176) 12.0(0.98000.414) 12.0(0.98000.531) 12.0(0.98000.536) 12.0(0.98000.6) 12.0(0.98500.8).
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | =12.0\(0.99000.9\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3802 is classified as a high severity vulnerability due to its potential to allow unauthenticated remote attackers to exploit it.
To fix CVE-2017-3802, you should upgrade Cisco Unified Communications Manager to a fixed release version as specified by Cisco.
CVE-2017-3802 allows for cross-site scripting (XSS) attacks through the web interface of the affected Cisco Unified Communications Manager.
CVE-2017-3802 affects Cisco Unified Communications Manager version 12.0(0.99000.9).
No, an attacker does not need to be authenticated to exploit CVE-2017-3802.