Junglewise Threat Intelligence

CVE-2017-3802: Cisco Unified Communications Manager XSS in web interface

CVE-2017-3802 · Severity: medium · CVSS 6.1 · Published 2017-01-26

Technologies: Cisco Unified Communications Manager. Vendors: Cisco.

Executive brief

Cisco Unified Communications Manager, a system used for managing enterprise voice and video calls, contains a security flaw in its web management interface. An attacker could trick a legitimate user into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the user's browser. This could lead to the theft of session information or unauthorized actions being performed on the management console.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the web interface of Cisco Unified Communications Manager (CUCM). The flaw is caused by the application's failure to properly invoke XSS filter subsystems when processing specific URL parameters. An unauthenticated remote attacker can exploit this by persuading a user to follow a specially crafted link or visit a malicious website. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the affected site, potentially leading to session hijacking or unauthorized administrative actions. The vulnerability is tracked as Cisco Bug ID CSCvc20679 and has been addressed in multiple fixed releases of version 12.0.

Affected products

  • Cisco Unified Communications Manager (CUCM) 12.0(0.99000.9)

Timeline

  • 2017-01-18: disclosed: Initial public release by Cisco
  • 2017-01-19: advisory: Updated technical information published by Cisco
  • 2017-01-26: advisory: NVD publication date

References

Related threats