CVE-2017-3836 (unified_communications_manager)

CVE-2017-3836 (unified_communications_manager)

A vulnerability in the web framework Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitive data. More Information: CSCvb61689. Known Affected Releases: 11.5(1.11007.2). Known Fixed Releases: 12.0(0.98000.162) 12.0(0.98000.178) 12.0(0.98000.383) 12.0(0.98000.488) 12.0(0.98000.536) 12.0(0.98000.6) 12.0(0.98500.6).

Source: CVE-2017-3836 (unified_communications_manager)

CVE-2017-3821 (unified_communications_manager)

CVE-2017-3821 (unified_communications_manager)

A vulnerability in the serviceability page of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct reflected cross-site scripting (XSS) attacks. More Information: CSCvc49348. Known Affected Releases: 10.5(2.14076.1). Known Fixed Releases: 12.0(0.98000.209) 12.0(0.98000.478) 12.0(0.98000.609).

Source: CVE-2017-3821 (unified_communications_manager)

CVE-2017-3840 (secure_access_control_system)

CVE-2017-3840 (secure_access_control_system)

A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect Vulnerability. More Information: CSCvc04849. Known Affected Releases: 5.8(2.5).

Source: CVE-2017-3840 (secure_access_control_system)

CVE-2017-3837 (meeting_server)

CVE-2017-3837 (meeting_server)

An HTTP Packet Processing vulnerability in the Web Bridge interface of the Cisco Meeting Server (CMS), formerly Acano Conferencing Server, could allow an authenticated, remote attacker to retrieve memory contents, which could lead to the disclosure of confidential information. In addition, the attacker could potentially cause the application to crash unexpectedly, resulting in a denial of service (DoS) condition. The attacker would need to be authenticated and have a valid session with the Web Bridge. Affected Products: This vulnerability affects Cisco Meeting Server software releases prior to 2.1.2. This product was previously known as Acano Conferencing Server. More Information: CSCvc89551. Known Affected Releases: 2.0 2.0.7 2.1. Known Fixed Releases: 2.1.2.

Source: CVE-2017-3837 (meeting_server)

CVE-2017-3838 (secure_access_control_system)

CVE-2017-3838 (secure_access_control_system)

A vulnerability in Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to conduct a DOM-based cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCvc04838. Known Affected Releases: 5.8(2.5).

Source: CVE-2017-3838 (secure_access_control_system)

CVE-2017-3839 (secure_access_control_system)

CVE-2017-3839 (secure_access_control_system)

An XML External Entity vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to have read access to part of the information stored in the affected system. More Information: CSCvc04845. Known Affected Releases: 5.8(2.5).

Source: CVE-2017-3839 (secure_access_control_system)

CVE-2017-3845 (prime_collaboration_assurance)

CVE-2017-3845 (prime_collaboration_assurance)

A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. Affected Products: Cisco Prime Collaboration Assurance software versions 11.0, 11.1, and 11.5 are vulnerable. Cisco Prime Collaboration Assurance software versions prior to 11.0 are not vulnerable. More Information: CSCvc77783. Known Affected Releases: 11.5(0).

Source: CVE-2017-3845 (prime_collaboration_assurance)

CVE-2017-3842 (intrusion_prevention_system_device_manager)

CVE-2017-3842 (intrusion_prevention_system_device_manager)

A vulnerability in the web-based management interface of the Cisco Intrusion Prevention System Device Manager (IDM) could allow an unauthenticated, remote attacker to view sensitive information stored in certain HTML comments. More Information: CSCuh91455. Known Affected Releases: 7.2(1)V7.

Source: CVE-2017-3842 (intrusion_prevention_system_device_manager)