Vulnslist

find the latest Cisco vulnerabilities

Multiple Cisco Unified Communications Products Open Redirect Vulnerability

cisco-sa-20181003-er-ucm-redirect · Medium · Published · Updated

A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Manager, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an authenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the parameters of an HTTP request. An attacker could exploit this vulnerability by crafting an HTTP request that causes the web interface to redirect a request to a specific malicious URL. This type of vulnerability is known as an open redirect attack and is used in phishing attacks that get users to unknowingly visit malicious sites. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181003-er-ucm-redirect

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2018-15403
Cisco Bug IDsCSCvj48070, CSCvj56757, CSCvj59218, CSCvj56760
CVSS ScoreBase 4.1
Base 4.1 CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Emergency Responder, Cisco Unity Connection, Cisco Unified Communications Manager, Cisco Unified Communications Manager IM and Presence Service

CSAF Product Statuses

Product Status Source CVE Rows
Cisco Emergency Responder known_affected cisco_csaf CVE-2018-15403 1
Cisco Unified Communications Manager known_affected cisco_csaf CVE-2018-15403 1
Cisco Unified Communications Manager IM and Presence Service known_affected cisco_csaf CVE-2018-15403 1
Cisco Unity Connection known_affected cisco_csaf CVE-2018-15403 1

Related Products

Product CVE Evidence
Cisco Emergency Responder CVE-2018-15403 Cisco OpenVuln
Cisco Unified Communications Manager CVE-2018-15403 Cisco OpenVuln
Cisco Unified Communications Manager IM and Presence Service CVE-2018-15403 Cisco OpenVuln
Cisco Unity CVE-2018-15403 Cisco OpenVuln
Cisco Unity Connection CVE-2018-15403 Cisco OpenVuln