MEDIUM · 6.1

CVE-2018-15434

A vulnerability in the web-based management interface of Cisco Unified IP Phone 7900 Series could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a use...

Vulnerability Description

A vulnerability in the web-based management interface of Cisco Unified IP Phone 7900 Series could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

CVSS Score

6.1

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
CiscoSkinny Client Control Protocol Software9.4\(2\)
CiscoUnified Ip Phones 7906GAll versions
CiscoUnified Ip Phones 7911GAll versions
CiscoUnified Ip Phones 7912GAll versions
CiscoUnified Ip Phones 7920 Multi-ChargerAll versions
CiscoUnified Ip Phones 7921GAll versions
CiscoUnified Ip Phones 7925GAll versions
CiscoUnified Ip Phones 7925G-ExAll versions
CiscoUnified Ip Phones 7926GAll versions
CiscoUnified Ip Phones 7931GAll versions
CiscoUnified Ip Phones 7940GAll versions
CiscoUnified Ip Phones 7941GAll versions
CiscoUnified Ip Phones 7942GAll versions
CiscoUnified Ip Phones 7945GAll versions
CiscoUnified Ip Phones 7960GAll versions
CiscoUnified Ip Phones 7961GAll versions
CiscoUnified Ip Phones 7962GAll versions
CiscoUnified Ip Phones 7965GAll versions
CiscoUnified Ip Phones 7975GAll versions
CiscoUnified Ip Phones Conference Station 7936All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-15434?

CVE-2018-15434 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A vulnerability in the web-based management interface of Cisco Unified IP Phone 7900 Series could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a use...

How severe is CVE-2018-15434?

CVE-2018-15434 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-15434?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Skinny Client Control Protocol Software, Cisco Unified Ip Phones 7906G, Cisco Unified Ip Phones 7911G, Cisco Unified Ip Phones 7912G, Cisco Unified Ip Phones 7920 Multi-Charger.