SQL Injection Vulnerability in Cisco Unified Communications Domain Manager
CVE-2017-6668
4.9MEDIUM
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 13 June 2017
Summary
A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager allows authenticated remote attackers to exploit SQL injection techniques. This could potentially enable them to execute arbitrary SQL queries, compromising the confidentiality of the system. Users of the affected product should promptly assess their configurations and implement necessary security measures to safeguard against this type of attack. Further details can be found in the linked advisories.
Affected Version(s)
Cisco Unified Communications Domain Manager Cisco Unified Communications Domain Manager
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved