CVE-2017-3872: XSS
A cross-site scripting (XSS) filter bypass vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct XSS attacks against a user of an affected device. More Information: CSCvc21620. Known Affected Releases: 10.5(2.14076.1). Known Fixed Releases: 12.0(0.98000.641) 12.0(0.98000.500) 12.0(0.98000.219).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 12.0(0.98000.641)Patch CSCvc21620 - Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 12.0(0.98000.500)Patch CSCvc21620 - Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 12.0(0.98000.219)Patch CSCvc21620
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3872?
The severity of CVE-2017-3872 is classified as high due to the potential for unauthenticated remote attackers to perform XSS attacks.
How do I fix CVE-2017-3872?
To fix CVE-2017-3872, you should upgrade Cisco Unified Communications Manager to a version that is not affected by this vulnerability.
Which versions of Cisco Unified Communications Manager are affected by CVE-2017-3872?
CVE-2017-3872 affects Cisco Unified Communications Manager versions 10.5(2.10000.5), 10.5(2.14076.1), 11.0(1.10000.10), and 11.5(1.10000.6).
What type of vulnerability is CVE-2017-3872?
CVE-2017-3872 is a cross-site scripting (XSS) filter bypass vulnerability.
Can CVE-2017-3872 be exploited without authentication?
Yes, CVE-2017-3872 can be exploited by unauthenticated remote attackers.