CVE-2017-3877
published 2017-03-17CVE-2017-3877: A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct a…
PriorityP432medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
EPSS
0.77%
51.8th percentile
A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web interface of the affected software. More Information: CSCvb70021. Known Affected Releases: 11.5(1.11007.2).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-76x7-mpx3-h3rw: A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct
ghsa_unreviewed·2022-05-17
CVE-2017-3877 [MEDIUM] CWE-352 GHSA-76x7-mpx3-h3rw: A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct
A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web interface of the affected software. More Information: CSCvb70021. Known Affected Releases: 11.5(1.11007.2).
OSV
libapache2-mod-auth-mellon vulnerabilities
osv·2020-10-22·CVSS 6.1
CVE-2017-6807 libapache2-mod-auth-mellon vulnerabilities
libapache2-mod-auth-mellon vulnerabilities
François Kooman discovered that mod_auth_mellon incorrectly handled
cookies. An attacker could possibly use this issue to cause a Cross-Site
Session Transfer attack. (CVE-2017-6807)
It was discovered that mod_auth_mellon incorrectly handled certain requests.
An attacker could possibly use this issue to redirect a user to a malicious
URL. (CVE-2019-3877)
It was discovered that mod_auth_mellon incorrectly handled certain requests.
An attacker could possibly use this issue to access sensitive information.
(CVE-2019-3878)
Cisco
Cisco Unified Communications Manager Cross-Site Request Forgery Vulnerability
vendor_cisco·2017-03-15·CVSS 6.5
CVE-2017-3877 [MEDIUM] CWE-352 Cisco Unified Communications Manager Cross-Site Request Forgery Vulnerability
Cisco Unified Communications Manager Cross-Site Request Forgery Vulnerability
A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web interface of the affected software.
The vulnerability is due to insufficient CSRF protections implemented by the affected software. An attacker could exploit this vulnerability by persuading a user of the web interface to follow a malicious link. A successful exploit could allow the attacker to submit arbitrary requests to the affected software via the user's web browser and with the user's privileges.
There are no workarounds that address this vulnerability.
This advisory is available at the f
Cisco
Cisco Unified Communications Manager Cross-Site Request Forgery Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-3877 Cisco Unified Communications Manager Cross-Site Request Forgery Vulnerability
CVE-2017-3877: Cisco Unified Communications Manager Cross-Site Request Forgery Vulnerability
A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web interface of the affected software. The vulnerability is due to insufficient CSRF protections implemented by the affected software. An attacker could exploit this vulnerability by persuading a user of the web interface to follow a malicious link. A successful exploit could allow the attacker to submit arbitrary requests to the affected software via the user's web browser and with the user's privileges. There are no
CVSS: 3.0
CWE: CWE-352, CWE-352
Bug IDs: CSCvb70021
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/96915http://www.securitytracker.com/id/1038038https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170315-ucm2http://www.securityfocus.com/bid/96915http://www.securitytracker.com/id/1038038https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170315-ucm2
2017-03-17
Published