CVE-2017-3829: XSS
A vulnerability in the web-based management interface of Cisco Unified Communications Manager Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvc30999. Known Affected Releases: 12.0(0.98000.280). Known Fixed Releases: 11.0(1.23900.3) 12.0(0.98000.180) 12.0(0.98000.422) 12.0(0.98000.541) 12.0(0.98000.6).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Unified Communications Manager Switches (web-based management interface)to a version that resolves this vulnerability.Fixed in 11.0(1.23900.3) - Upgrade
Upgrade
Cisco Unified Communications Manager Switches (web-based management interface)to a version that resolves this vulnerability.Fixed in 12.0(0.98000.180) - Upgrade
Upgrade
Cisco Unified Communications Manager Switches (web-based management interface)to a version that resolves this vulnerability.Fixed in 12.0(0.98000.422) - Upgrade
Upgrade
Cisco Unified Communications Manager Switches (web-based management interface)to a version that resolves this vulnerability.Fixed in 12.0(0.98000.541) - Upgrade
Upgrade
Cisco Unified Communications Manager Switches (web-based management interface)to a version that resolves this vulnerability.Fixed in 12.0(0.98000.6) - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CSCvc30999
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3829?
CVE-2017-3829 is rated as a high-severity vulnerability due to its potential for allowing cross-site scripting (XSS) attacks.
How do I fix CVE-2017-3829?
To mitigate CVE-2017-3829, it is recommended to upgrade to the latest version of Cisco Unified Communications Manager.
Who is affected by CVE-2017-3829?
CVE-2017-3829 affects users of Cisco Unified Communications Manager versions 11.0(1.10000.10) and 11.5(1.10000.6).
What type of attack is possible with CVE-2017-3829?
CVE-2017-3829 could allow an unauthenticated remote attacker to conduct a cross-site scripting (XSS) attack.
Is authentication required to exploit CVE-2017-3829?
No, CVE-2017-3829 can be exploited by an unauthenticated attacker, making it particularly concerning.