CVE-2017-6670
published 2017-06-13CVE-2017-6670: A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user to a…
PriorityP427medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.20%
64.6th percentile
A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect issue. More Information: CSCvc54813. Known Affected Releases: 8.1(7)ER1.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_domain_manager | — | — |
| cisco | unified_communications_domain_manager_open_redirect | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_cisco6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r3wx-q354-fc7x: A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user
ghsa_unreviewed·2022-05-17
CVE-2017-6670 [MEDIUM] CWE-601 GHSA-r3wx-q354-fc7x: A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user
A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect issue. More Information: CSCvc54813. Known Affected Releases: 8.1(7)ER1.
Cisco
Cisco Unified Communications Domain Manager Open Redirect Vulnerability
vendor_cisco·2017-06-07·CVSS 6.1
CVE-2017-6670 [MEDIUM] CWE-20 Cisco Unified Communications Domain Manager Open Redirect Vulnerability
Cisco Unified Communications Domain Manager Open Redirect Vulnerability
A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.
The vulnerability is due to improper input validation of HTTP request parameters by the affected software. An attacker could exploit this vulnerability by submitting a crafted HTTP request to the web interface of the affected software, which could cause the web interface to redirect the request to a malicious web page at a specified URL. This vulnerability is referred to as an open redirect attack and is used in phishing attacks that cause users to unknowingly visit malicious sites.
There are no workarounds that address this vulnerability.
Th
Cisco
Cisco Unified Communications Domain Manager Open Redirect Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-6670 Cisco Unified Communications Domain Manager Open Redirect Vulnerability
CVE-2017-6670: Cisco Unified Communications Domain Manager Open Redirect Vulnerability
A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of HTTP request parameters by the affected software. An attacker could exploit this vulnerability by submitting a crafted HTTP request to the web interface of the affected software, which could cause the web interface to redirect the request to a malicious web page at a specified URL. This vulnerability is referred to as an open redirect attack and is used in phishing attacks that cause users to unknowingly visit malicious sites. There are no
CVSS: 3.0
CWE: CWE-20, CWE-20
Bug ID
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/98946http://www.securitytracker.com/id/1038631https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-cucm1http://www.securityfocus.com/bid/98946http://www.securitytracker.com/id/1038631https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-cucm1
2017-06-13
Published