PT-2019-3812 · Cisco · Unity Connection+3

Published

2019-10-02

·

Updated

2019-10-11

·

CVE-2019-12707

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Unified Communications Manager versions (affected versions not specified) Cisco Unified Communications Manager SME versions (affected versions not specified) Unified Communications Manager IM and Presence Service versions (affected versions not specified) Unity Connection versions (affected versions not specified)
Description The issue exists due to insufficient protection of the web page structure in the web-based interface of the affected software. An attacker could exploit this by persuading a user to click a specially crafted link, potentially allowing the execution of arbitrary code or access to confidential information. The vulnerability is also described as allowing an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface.
Recommendations For Cisco Unified Communications Manager, consider disabling access to the web-based interface until a patch is available. For Cisco Unified Communications Manager SME, restrict access to the web-based interface to minimize the risk of exploitation. For Unified Communications Manager IM and Presence Service, avoid using the web-based interface for sensitive operations until the issue is resolved. For Unity Connection, as a temporary workaround, consider implementing additional validation of user-supplied input to the web-based interface. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04139
CVE-2019-12707

Affected Products

Cisco Unified Communications Manager
Cisco Unified Communications Manager Sme
Cisco Unified Communications Manager Im & Presence Service
Unity Connection