CVE-2017-3888: XSS
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability affects Cisco Unified Communications Manager with a default configuration running an affected software release with the attacker authenticated as the administrative user. More Information: CSCvc83712. Known Affected Releases: 12.0(0.98000.452). Known Fixed Releases: 12.0(0.98000.750) 12.0(0.98000.708) 12.0(0.98000.707) 12.0(0.98000.704) 12.0(0.98000.554) 12.0(0.98000.546) 12.0(0.98000.543) 12.0(0.98000.248) 12.0(0.98000.244) 12.0(0.98000.242).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 12.0(0.98000.750)Patch CSCvc83712 - Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 12.0(0.98000.708)Patch CSCvc83712 - Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 12.0(0.98000.707)Patch CSCvc83712 - Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 12.0(0.98000.704)Patch CSCvc83712 - Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 12.0(0.98000.554)Patch CSCvc83712 - Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 12.0(0.98000.546)Patch CSCvc83712 - Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 12.0(0.98000.543)Patch CSCvc83712 - Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 12.0(0.98000.248)Patch CSCvc83712 - Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 12.0(0.98000.244)Patch CSCvc83712 - Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 12.0(0.98000.242)Patch CSCvc83712
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3888?
CVE-2017-3888 is classified as a medium severity vulnerability due to the potential for reflected cross-site scripting attacks.
How do I fix CVE-2017-3888?
To fix CVE-2017-3888, update to the latest version of Cisco Unified Communications Manager that addresses this vulnerability.
What systems are affected by CVE-2017-3888?
CVE-2017-3888 specifically affects Cisco Unified Communications Manager version 12.0(0.98000.452).
Can CVE-2017-3888 be exploited remotely?
Yes, CVE-2017-3888 can be exploited by an authenticated remote attacker through the web-based management interface.
What type of attack does CVE-2017-3888 enable?
CVE-2017-3888 potentially enables reflected cross-site scripting (XSS) attacks against users of the affected web interface.