First published: Wed Feb 22 2017(Updated: )
A vulnerability in the serviceability page of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct reflected cross-site scripting (XSS) attacks. More Information: CSCvc49348. Known Affected Releases: 10.5(2.14076.1). Known Fixed Releases: 12.0(0.98000.209) 12.0(0.98000.478) 12.0(0.98000.609).
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | =10.5\(2.14076.1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3821 is classified as a medium severity vulnerability, enabling reflected cross-site scripting attacks.
To remediate CVE-2017-3821, upgrade the Cisco Unified Communications Manager to a fixed release, specifically 12.0(0.98000.209) or later.
CVE-2017-3821 allows unauthenticated remote attackers to execute reflected cross-site scripting (XSS) attacks.
CVE-2017-3821 affects the Cisco Unified Communications Manager version 10.5(2.14076.1) specifically.
No, exploitation of CVE-2017-3821 does not require authentication, allowing unauthenticated attackers to potentially exploit it.