CVE-2017-6722
published 2017-07-04CVE-2017-6722: A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated…
PriorityP431medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.15%
63.7th percentile
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated, remote attacker to masquerade as a legitimate user, aka a Clear Text Authentication Vulnerability. More Information: CSCuw86638. Known Affected Releases: 10.6(1). Known Fixed Releases: 11.5(1.10000.61).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_contact_center_express | — | — |
| cisco | unified_contact_center_express | — | — |
| cisco | unified_contact_center_express | — | — |
| cisco | unified_contact_center_express_clear_text | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
vendor_cisco6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Contact Center Express Clear Text Authentication Vulnerability
vendor_cisco·2017-06-21·CVSS 6.1
CVE-2017-6722 [MEDIUM] CWE-287 Cisco Unified Contact Center Express Clear Text Authentication Vulnerability
Cisco Unified Contact Center Express Clear Text Authentication Vulnerability
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated, remote attacker to masquerade as a legitimate user.
The vulnerability is due to the XMPP service incorrectly processing an unsecured HTTP port for third-party, remote presence monitoring. A successful exploit could allow the attacker to access the system as another user.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-ucce
Cisco
Cisco Unified Contact Center Express Clear Text Authentication Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-6722 Cisco Unified Contact Center Express Clear Text Authentication Vulnerability
CVE-2017-6722: Cisco Unified Contact Center Express Clear Text Authentication Vulnerability
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated, remote attacker to masquerade as a legitimate user. The vulnerability is due to the XMPP service incorrectly processing an unsecured HTTP port for third-party, remote presence monitoring. A successful exploit could allow the attacker to access the system as another user. There are no
CVSS: 3.0
CWE: CWE-287, CWE-287
Bug IDs: CSCuw86638
GHSA
GHSA-r8qw-7chv-8gcx: A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthe
ghsa_unreviewed·2022-05-17
CVE-2017-6722 [MEDIUM] CWE-287 GHSA-r8qw-7chv-8gcx: A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthe
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated, remote attacker to masquerade as a legitimate user, aka a Clear Text Authentication Vulnerability. More Information: CSCuw86638. Known Affected Releases: 10.6(1). Known Fixed Releases: 11.5(1.10000.61).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/99201http://www.securitytracker.com/id/1038749https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-uccehttp://www.securityfocus.com/bid/99201http://www.securitytracker.com/id/1038749https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-ucce
2017-07-04
Published