ID

VAR-201902-0453


CVE

CVE-2019-1685


TITLE

Cisco Unity Connection Vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2019-001930

DESCRIPTION

A vulnerability in the Security Assertion Markup Language (SAML) single sign-on (SSO) interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Version 12.5 is affected. Cisco Unity Connection Contains a cross-site scripting vulnerability.Information may be obtained and information may be altered. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue is being tracked by Cisco Bug ID CSCvk29994. The platform can utilize voice commands to make calls or listen to messages hands-free

Trust: 1.98

sources: NVD: CVE-2019-1685 // JVNDB: JVNDB-2019-001930 // BID: 107102 // VULHUB: VHN-149037

AFFECTED PRODUCTS

vendor:ciscomodel:unity connectionscope:eqversion:12.5

Trust: 2.1

sources: BID: 107102 // JVNDB: JVNDB-2019-001930 // NVD: CVE-2019-1685

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-1685
value: MEDIUM

Trust: 1.0

ykramarz@cisco.com: CVE-2019-1685
value: MEDIUM

Trust: 1.0

NVD: CVE-2019-1685
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201902-800
value: MEDIUM

Trust: 0.6

VULHUB: VHN-149037
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2019-1685
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-149037
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

ykramarz@cisco.com: CVE-2019-1685
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.0

Trust: 1.8

nvd@nist.gov: CVE-2019-1685
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.1

Trust: 1.0

sources: VULHUB: VHN-149037 // JVNDB: JVNDB-2019-001930 // CNNVD: CNNVD-201902-800 // NVD: CVE-2019-1685 // NVD: CVE-2019-1685

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-149037 // JVNDB: JVNDB-2019-001930 // NVD: CVE-2019-1685

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201902-800

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201902-800

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-001930

PATCH

title:cisco-sa-20190220-cuc-rxssurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190220-cuc-rxss

Trust: 0.8

title:Cisco Unity Connection Fixes for cross-site scripting vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=89594

Trust: 0.6

sources: JVNDB: JVNDB-2019-001930 // CNNVD: CNNVD-201902-800

EXTERNAL IDS

db:NVDid:CVE-2019-1685

Trust: 2.8

db:BIDid:107102

Trust: 2.0

db:JVNDBid:JVNDB-2019-001930

Trust: 0.8

db:CNNVDid:CNNVD-201902-800

Trust: 0.7

db:NSFOCUSid:42805

Trust: 0.6

db:AUSCERTid:ESB-2019.0539

Trust: 0.6

db:VULHUBid:VHN-149037

Trust: 0.1

sources: VULHUB: VHN-149037 // BID: 107102 // JVNDB: JVNDB-2019-001930 // CNNVD: CNNVD-201902-800 // NVD: CVE-2019-1685

REFERENCES

url:http://www.securityfocus.com/bid/107102

Trust: 2.3

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190220-cuc-rxss

Trust: 2.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-1685

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-1685

Trust: 0.8

url:http://www.nsfocus.net/vulndb/42805

Trust: 0.6

url:https://www.auscert.org.au/bulletins/75902

Trust: 0.6

url:http://www.cisco.com/

Trust: 0.3

url:http://www.cisco.com/c/en/us/products/unified-communications/unity-connection/index.html

Trust: 0.3

sources: VULHUB: VHN-149037 // BID: 107102 // JVNDB: JVNDB-2019-001930 // CNNVD: CNNVD-201902-800 // NVD: CVE-2019-1685

CREDITS

The vendor reported this issue.,Cisco      ,This vulnerability was found during the resolution of a Cisco TAC support case.

Trust: 0.6

sources: CNNVD: CNNVD-201902-800

SOURCES

db:VULHUBid:VHN-149037
db:BIDid:107102
db:JVNDBid:JVNDB-2019-001930
db:CNNVDid:CNNVD-201902-800
db:NVDid:CVE-2019-1685

LAST UPDATE DATE

2024-08-14T13:26:58.436000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-149037date:2019-10-09T00:00:00
db:BIDid:107102date:2019-02-20T00:00:00
db:JVNDBid:JVNDB-2019-001930date:2019-03-29T00:00:00
db:CNNVDid:CNNVD-201902-800date:2023-03-24T00:00:00
db:NVDid:CVE-2019-1685date:2023-03-23T17:34:20.717

SOURCES RELEASE DATE

db:VULHUBid:VHN-149037date:2019-02-21T00:00:00
db:BIDid:107102date:2019-02-20T00:00:00
db:JVNDBid:JVNDB-2019-001930date:2019-03-29T00:00:00
db:CNNVDid:CNNVD-201902-800date:2019-02-20T00:00:00
db:NVDid:CVE-2019-1685date:2019-02-21T20:29:00.367