ID

VAR-201711-0351


CVE

CVE-2017-12356


TITLE

Cisco Jabber Vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2017-010408

DESCRIPTION

A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvf50378, CSCvg56018. Cisco Jabber Contains a cross-site scripting vulnerability. Vendors have confirmed this vulnerability Bug ID CSCvf50378 and CSCvg56018 It is released as.Information may be obtained and information may be altered. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. Cisco Jabber for Windows, Mac, Android and iOS is a set of unified communication client solutions of Cisco for Windows, Mac, Android and iOS platforms. The program provides online status display, instant messaging, voice and other functions

Trust: 1.98

sources: NVD: CVE-2017-12356 // JVNDB: JVNDB-2017-010408 // BID: 101990 // VULHUB: VHN-102870

AFFECTED PRODUCTS

vendor:ciscomodel:jabberscope:eqversion:10.5\(2\)

Trust: 1.6

vendor:ciscomodel:jabberscope:eqversion: -

Trust: 1.6

vendor:ciscomodel:jabberscope:eqversion:11.9\(1\)

Trust: 1.6

vendor:ciscomodel:jabberscope: - version: -

Trust: 0.8

vendor:ciscomodel:jabber for windowsscope:eqversion:11.9(1)

Trust: 0.3

vendor:ciscomodel:jabber for windowsscope:eqversion:10.5(2)

Trust: 0.3

vendor:ciscomodel:jabber for windowsscope:eqversion:0

Trust: 0.3

vendor:ciscomodel:jabber for macscope:eqversion:0

Trust: 0.3

vendor:ciscomodel:jabber for iosscope:eqversion:0

Trust: 0.3

vendor:ciscomodel:jabber for androidscope:eqversion:0

Trust: 0.3

vendor:ciscomodel:jabber for windowsscope:neversion:11.9(2.57651)

Trust: 0.3

sources: BID: 101990 // JVNDB: JVNDB-2017-010408 // CNNVD: CNNVD-201711-1210 // NVD: CVE-2017-12356

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-12356
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-12356
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201711-1210
value: MEDIUM

Trust: 0.6

VULHUB: VHN-102870
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-12356
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-102870
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-12356
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-102870 // JVNDB: JVNDB-2017-010408 // CNNVD: CNNVD-201711-1210 // NVD: CVE-2017-12356

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-102870 // JVNDB: JVNDB-2017-010408 // NVD: CVE-2017-12356

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201711-1210

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201711-1210

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-010408

PATCH

title:cisco-sa-20171129-jabberurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171129-jabber

Trust: 0.8

title:Cisco Jabber for Windows , Mac , Android and iOS Cisco Jabber Fixes for cross-site scripting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=76829

Trust: 0.6

sources: JVNDB: JVNDB-2017-010408 // CNNVD: CNNVD-201711-1210

EXTERNAL IDS

db:NVDid:CVE-2017-12356

Trust: 2.8

db:BIDid:101990

Trust: 2.0

db:SECTRACKid:1039914

Trust: 1.7

db:JVNDBid:JVNDB-2017-010408

Trust: 0.8

db:CNNVDid:CNNVD-201711-1210

Trust: 0.6

db:VULHUBid:VHN-102870

Trust: 0.1

sources: VULHUB: VHN-102870 // BID: 101990 // JVNDB: JVNDB-2017-010408 // CNNVD: CNNVD-201711-1210 // NVD: CVE-2017-12356

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20171129-jabber

Trust: 2.0

url:http://www.securityfocus.com/bid/101990

Trust: 1.7

url:http://www.securitytracker.com/id/1039914

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-12356

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-12356

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-102870 // BID: 101990 // JVNDB: JVNDB-2017-010408 // CNNVD: CNNVD-201711-1210 // NVD: CVE-2017-12356

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 101990

SOURCES

db:VULHUBid:VHN-102870
db:BIDid:101990
db:JVNDBid:JVNDB-2017-010408
db:CNNVDid:CNNVD-201711-1210
db:NVDid:CVE-2017-12356

LAST UPDATE DATE

2024-11-23T21:53:38.360000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-102870date:2019-10-09T00:00:00
db:BIDid:101990date:2017-12-19T22:01:00
db:JVNDBid:JVNDB-2017-010408date:2017-12-13T00:00:00
db:CNNVDid:CNNVD-201711-1210date:2019-10-17T00:00:00
db:NVDid:CVE-2017-12356date:2024-11-21T03:09:22.357

SOURCES RELEASE DATE

db:VULHUBid:VHN-102870date:2017-11-30T00:00:00
db:BIDid:101990date:2017-11-29T00:00:00
db:JVNDBid:JVNDB-2017-010408date:2017-12-13T00:00:00
db:CNNVDid:CNNVD-201711-1210date:2017-12-01T00:00:00
db:NVDid:CVE-2017-12356date:2017-11-30T09:29:01.167