Junglewise Threat Intelligence

CVE-2017-3798: Cisco Unified Communications Manager XSS filter bypass in web interface

CVE-2017-3798 · Severity: medium · CVSS 6.1 · Published 2017-01-26

Technologies: Cisco Unified Communications Manager. Vendors: Cisco.

Executive brief

Cisco Unified Communications Manager, a system used for managing enterprise IP telephony and video calls, contains a security flaw in its web management interface. An attacker could trick a system administrator into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the administrator's browser. This could lead to the theft of sensitive session information or unauthorized actions being performed within the management console.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the web-based management interface of Cisco Unified Communications Manager (CUCM). The flaw is caused by a failure to properly invoke XSS filter subsystems when specific parameters are present in a URL. An unauthenticated remote attacker can exploit this by persuading a user of the interface to click a specially crafted link. Successful exploitation allows the attacker to execute arbitrary script code in the context of the affected site, potentially leading to session hijacking or unauthorized configuration changes. Fixed releases include 11.5(1.12029.1), 12.0(0.98000.369), and subsequent versions.

Affected products

  • Cisco Unified Communications Manager (CUCM) 11.0(1.10000.10), 11.5(1.10000.6)

Timeline

  • 2017-01-18: advisory: Initial Cisco advisory release
  • 2017-01-26: disclosed: NVD publication date

References

Related threats