383
VMScore

CVE-2017-3872

Published: 17/03/2017 Updated: 22/04/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A cross-site scripting (XSS) filter bypass vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote malicious user to conduct XSS attacks against a user of an affected device. More Information: CSCvc21620. Known Affected Releases: 10.5(2.14076.1). Known Fixed Releases: 12.0(0.98000.641) 12.0(0.98000.500) 12.0(0.98000.219).

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified communications manager 11.0\\(1.10000.10\\)

cisco unified communications manager 11.5\\(1.10000.6\\)

cisco unified communications manager 10.5\\(2.14076.1\\)

cisco unified communications manager 10.5\\(2.10000.5\\)