Medium severity6.1NVD Advisory· Published Mar 17, 2017· Updated May 13, 2026
CVE-2017-3872
CVE-2017-3872
Description
A cross-site scripting (XSS) filter bypass vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct XSS attacks against a user of an affected device. More Information: CSCvc21620. Known Affected Releases: 10.5(2.14076.1). Known Fixed Releases: 12.0(0.98000.641) 12.0(0.98000.500) 12.0(0.98000.219).
Affected products
5cpe:2.3:a:cisco:unified_communications_manager:10.5\(2.10000.5\):*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:cisco:unified_communications_manager:10.5\(2.10000.5\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_communications_manager:10.5\(2.14076.1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_communications_manager:11.0\(1.10000.10\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:unified_communications_manager:11.5\(1.10000.6\):*:*:*:*:*:*:*
- Range: Cisco Unified Communications Manager
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/96916nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1038036nvdThird Party AdvisoryVDB Entry
- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170315-ucmnvdVendor Advisory
News mentions
0No linked articles in our index yet.