CVE-2018-0355Improper Input Validation in Cisco Unified Communications Manager

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 46.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 7
Latest updateMay 13

Description

A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to conduct a cross-frame scripting (XFS) attack against the user of the web UI of an affected system. The vulnerability is due to insufficient protections for HTML inline frames (iframes) by the web UI of the affected software. An attacker could exploit this vulnerability by persuading a user of the affected UI to navigate to an attacker-controlled web page that cont

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-764h-w597-g25g: A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to conduct a cross-2022-05-13
CVEList
CVE-2018-0355: A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to conduct a cross-2018-06-07

📋Vendor Advisories

1
Cisco
Cisco Unified Communications Manager Cross-Frame Scripting Vulnerability2018-06-06
CVE-2018-0355 — Improper Input Validation in Cisco | cvebase