CVE-2017-6722: Medium severity cisco unified contact center express enhanced vulnerability
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated, remote attacker to masquerade as a legitimate user, aka a Clear Text Authentication Vulnerability. More Information: CSCuw86638. Known Affected Releases: 10.6(1). Known Fixed Releases: 11.5(1.10000.61).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6722?
CVE-2017-6722 is classified as a high-severity vulnerability due to the potential for unauthorized access.
How do I fix CVE-2017-6722?
To fix CVE-2017-6722, Cisco advises updating to the latest patched versions of the Cisco Unified Contact Center Express.
What type of attack does CVE-2017-6722 enable?
CVE-2017-6722 allows an unauthenticated, remote attacker to masquerade as a legitimate user on the XMPP service.
Which versions of Cisco Unified Contact Center Express are affected by CVE-2017-6722?
The affected versions include Cisco Unified Contact Center Express 11.5(1), 11.5.1es01, and 11.5.1su1.
Is authentication required to exploit CVE-2017-6722?
No, CVE-2017-6722 can be exploited without authentication, making it particularly dangerous.