ID

VAR-201512-0423


CVE

CVE-2015-6390


TITLE

Cisco Unity Connection Management interface cross-site scripting vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2015-006078

DESCRIPTION

Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unity Connection 9.1(1.10) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCup92741. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue is being tracked by Cisco Bug IDs CSCup92741 and CSCux34306. Cisco Unity Connection (UC) is a set of voice message platform of Cisco (Cisco). The platform can use voice commands to make calls or listen to messages "hands-free"

Trust: 2.07

sources: NVD: CVE-2015-6390 // JVNDB: JVNDB-2015-006078 // BID: 78480 // VULHUB: VHN-84351 // VULMON: CVE-2015-6390

AFFECTED PRODUCTS

vendor:ciscomodel:unity connectionscope:eqversion:9.1\(1.10\)

Trust: 1.6

vendor:ciscomodel:unity connectionscope:eqversion:9.1(1.10)

Trust: 1.1

sources: BID: 78480 // JVNDB: JVNDB-2015-006078 // CNNVD: CNNVD-201512-028 // NVD: CVE-2015-6390

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-6390
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-6390
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201512-028
value: MEDIUM

Trust: 0.6

VULHUB: VHN-84351
value: MEDIUM

Trust: 0.1

VULMON: CVE-2015-6390
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-6390
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-84351
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-84351 // VULMON: CVE-2015-6390 // JVNDB: JVNDB-2015-006078 // CNNVD: CNNVD-201512-028 // NVD: CVE-2015-6390

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-84351 // JVNDB: JVNDB-2015-006078 // NVD: CVE-2015-6390

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201512-028

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201512-028

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-006078

PATCH

title:cisco-sa-20151202-pcaurl:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151202-pca

Trust: 0.8

title:Cisco Unity Connection Fixes for cross-site scripting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=58895

Trust: 0.6

title:Cisco: Cisco Unity Connection Cross-Site Scripting Vulnerabilityurl:https://vulmon.com/vendoradvisory?qidtp=cisco_security_advisories_and_alerts_ciscoproducts&qid=cisco-sa-20151202-pca

Trust: 0.1

sources: VULMON: CVE-2015-6390 // JVNDB: JVNDB-2015-006078 // CNNVD: CNNVD-201512-028

EXTERNAL IDS

db:NVDid:CVE-2015-6390

Trust: 2.9

db:SECTRACKid:1034286

Trust: 1.2

db:JVNDBid:JVNDB-2015-006078

Trust: 0.8

db:CNNVDid:CNNVD-201512-028

Trust: 0.7

db:BIDid:78480

Trust: 0.5

db:SEEBUGid:SSVID-89995

Trust: 0.1

db:VULHUBid:VHN-84351

Trust: 0.1

db:VULMONid:CVE-2015-6390

Trust: 0.1

sources: VULHUB: VHN-84351 // VULMON: CVE-2015-6390 // BID: 78480 // JVNDB: JVNDB-2015-006078 // CNNVD: CNNVD-201512-028 // NVD: CVE-2015-6390

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20151202-pca

Trust: 1.9

url:http://www.securitytracker.com/id/1034286

Trust: 1.2

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-6390

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-6390

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20151202-pca

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/79.html

Trust: 0.1

url:https://www.securityfocus.com/bid/78480

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-84351 // VULMON: CVE-2015-6390 // BID: 78480 // JVNDB: JVNDB-2015-006078 // CNNVD: CNNVD-201512-028 // NVD: CVE-2015-6390

CREDITS

Cisco

Trust: 0.3

sources: BID: 78480

SOURCES

db:VULHUBid:VHN-84351
db:VULMONid:CVE-2015-6390
db:BIDid:78480
db:JVNDBid:JVNDB-2015-006078
db:CNNVDid:CNNVD-201512-028
db:NVDid:CVE-2015-6390

LAST UPDATE DATE

2024-11-23T23:09:13.325000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-84351date:2017-09-14T00:00:00
db:VULMONid:CVE-2015-6390date:2017-09-14T00:00:00
db:BIDid:78480date:2015-12-02T00:00:00
db:JVNDBid:JVNDB-2015-006078date:2015-12-04T00:00:00
db:CNNVDid:CNNVD-201512-028date:2015-12-03T00:00:00
db:NVDid:CVE-2015-6390date:2024-11-21T02:34:54.583

SOURCES RELEASE DATE

db:VULHUBid:VHN-84351date:2015-12-03T00:00:00
db:VULMONid:CVE-2015-6390date:2015-12-03T00:00:00
db:BIDid:78480date:2015-12-02T00:00:00
db:JVNDBid:JVNDB-2015-006078date:2015-12-04T00:00:00
db:CNNVDid:CNNVD-201512-028date:2015-12-03T00:00:00
db:NVDid:CVE-2015-6390date:2015-12-03T03:59:02