CVE-2020-3282

A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
ciscoCNA
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
VendorProductVersion
ciscounified_communications_manager
10.5\(2\) ≤
𝑥
< 10.5\(2\)su10
ciscounified_communications_manager
10.5\(2\) ≤
𝑥
< 10.5\(2\)su10
ciscounified_communications_manager
11.5\(1\) ≤
𝑥
< 11.5\(1\)su8
ciscounified_communications_manager
11.5\(1\) ≤
𝑥
< 11.5\(1\)su8
ciscounified_communications_manager
12.0\(1\)
ciscounified_communications_manager
12.0\(1\)
ciscounified_communications_manager
12.5\(1\)
ciscounified_communications_manager
12.5\(1\)
ciscounified_communications_manager_im_and_presence_service
10.5\(2\) ≤
𝑥
< 10.5\(2\)su10
ciscounified_communications_manager_im_and_presence_service
11.5\(1\) ≤
𝑥
< 11.5\(1\)su8
ciscounified_communications_manager_im_and_presence_service
12.0\(1\)
ciscounified_communications_manager_im_and_presence_service
12.5\(1\)
ciscounity_connection
10.5\(2\) ≤
𝑥
< 10.5\(2\)su10
ciscounity_connection
11.5\(1\) ≤
𝑥
< 11.5\(1\)su8
ciscounity_connection
12.0\(1\)
ciscounity_connection
12.5\(1\)
𝑥
= Vulnerable software versions