CVE-2017-6789
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the Cisco Unified Intelligence Center web interface could allow an unauthenticated, remote attacker to impact the integrity of the system by executing a Document Object Model (DOM)-based, environment or client-side cross-site scripting (XSS) attack. The vulnerability occurs because user-supplied data in the DOM input is not validated. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious DOM statements to the affected system. A successful exploit could allow the attacker to affect the integrity of the system by manipulating the database. Known Affected Releases 11.0(1)ES10. Cisco Bug IDs: CSCvf18325.
Una vulnerabilidad en la interfaz web de Cisco Unified Intelligence Center podría permitir que un atacante remoto sin autenticar afecte a la integridad del sistema ejecutando un ataque de Cross-Site Scripting (XSS) basado en DOM, en el entorno o del lado del cliente. Esta vulnerabilidad ocurre porque los datos proporcionados por el cliente en la entrada DOM no se validan. Un atacante podría explotar esta vulnerabilidad mediante el envío de URL modificadas que incluyan instrucciones DOM maliciosas al sistema afectado. Si se explota esta vulnerabilidad con éxito, un atacante podría afectar la integridad del sistema manipulando la base de datos. Versiones afectadas conocidas 11.0(1)ES10. Cisco Bug IDs: CSCvf18325.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-03-09 CVE Reserved
- 2017-09-07 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/100646 | Third Party Advisory | |
http://www.securitytracker.com/id/1039278 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Unified Intelligence Center Search vendor "Cisco" for product "Unified Intelligence Center" | 11.0\(1\)es10 Search vendor "Cisco" for product "Unified Intelligence Center" and version "11.0\(1\)es10" | - |
Affected
|