CVE-2017-3821: XSS
A vulnerability in the serviceability page of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct reflected cross-site scripting (XSS) attacks. More Information: CSCvc49348. Known Affected Releases: 10.5(2.14076.1). Known Fixed Releases: 12.0(0.98000.209) 12.0(0.98000.478) 12.0(0.98000.609).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 12.0(0.98000.209) - Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 12.0(0.98000.478) - Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 12.0(0.98000.609)
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3821?
CVE-2017-3821 is classified as a medium severity vulnerability, enabling reflected cross-site scripting attacks.
How do I fix CVE-2017-3821?
To remediate CVE-2017-3821, upgrade the Cisco Unified Communications Manager to a fixed release, specifically 12.0(0.98000.209) or later.
What types of attacks are possible with CVE-2017-3821?
CVE-2017-3821 allows unauthenticated remote attackers to execute reflected cross-site scripting (XSS) attacks.
What software versions are affected by CVE-2017-3821?
CVE-2017-3821 affects the Cisco Unified Communications Manager version 10.5(2.14076.1) specifically.
Is authentication required to exploit CVE-2017-3821?
No, exploitation of CVE-2017-3821 does not require authentication, allowing unauthenticated attackers to potentially exploit it.