Wednesday, July 18, 2018

Multiple Vulnerabilities in Cisco Unified Contact Center Express

Four vulnerabilities in Cisco Unified CCX could allow an unauthenticated, remote attacker to conduct XSS attacks against a user of the interface, conduct a CSRF attack, or retrieve a cleartext password.

The vulnerabilities are not dependent on one another; exploitation of one of the vulnerabilities is not required to exploit another vulnerability. In addition, a software release that is affected by one of the vulnerabilities may not be affected by the other vulnerabilities.

Details about the vulnerabilities are as follows.

Cisco Unified Contact Center Express Stored Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct a stored XSS attack against a user of the web-based interface of an affected application.

The vulnerability is due to insufficient validation of user-supplied input by the web-based interface of an affected application. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information.

The Common Vulnerabilities and Exposures (CVE) ID for this vulnerability is: CVE-2018-0400

The Common Vulnerability Scoring System (CVSS) Base score for this vulnerability is: 6.1

The Cisco bug ID for this vulnerability is: CSCvg70904

Cisco Unified Contact Center Express Reflected Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Unified CCX could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the web-based interface of an affected application.

The vulnerability is due to insufficient validation of user-supplied input by the web-based interface of an affected application. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information.

The CVE ID for this vulnerability is: CVE-2018-0401

The CVSS Base score for this vulnerability is: 6.1

The Cisco bug ID for this vulnerability is: CSCvg70967

Cisco Unified Contact Center Express Cross-Site Request Forgery Vulnerability

A vulnerability in the web-based management interface of Cisco Unified CCX could allow an unauthenticated, remote attacker to conduct a CSRF attack and perform arbitrary actions on an affected application.

The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to download, create, modify, and delete metadata files that are part of the Repository Datastore (RDS) on a targeted device via a web browser and with the privileges of the user.

For additional information about cross-site request forgery attacks and potential mitigation methods, see the action link in the right sidebar of this advisory.

The CVE ID for this vulnerability is: CVE-2018-0402

The CVSS Base score for this vulnerability is: 6.3

The Cisco bug ID for this vulnerability is: CSCvg70921

Cisco Unified Contact Center Express Information Disclosure Vulnerability

A vulnerability in the web-based management interface of Cisco Unified CCX could allow an unauthenticated, remote attacker to retrieve a cleartext password.

The vulnerability occurs because the application prefills the password field with a previously saved password from an internal database. An attacker could exploit this vulnerability by viewing the HTML source of an affected login form.

The CVE ID for this vulnerability is: CVE-2018-0403

The CVSS Base score for this vulnerability is: 5.3

The Cisco bug ID for this vulnerability is: CSCvg71040



from Cisco Security Advisory https://ift.tt/2Nqs7Fz

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.