4.8
CVE-2025-20361
- EPSS 0.03%
- Published 01.10.2025 17:15:39
- Last modified 02.10.2025 19:11:46
- Source psirt@cisco.com
- Teams watchlist Login
- Open Login
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid administrative credentials.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorCisco
≫
Product
Cisco Unified Communications Manager
Default Statusunknown
Version
12.5(1)SU2
Status
affected
Version
12.5(1)SU1
Status
affected
Version
12.5(1)
Status
affected
Version
12.5(1)SU3
Status
affected
Version
12.5(1)SU4
Status
affected
Version
14
Status
affected
Version
12.5(1)SU5
Status
affected
Version
14SU1
Status
affected
Version
12.5(1)SU6
Status
affected
Version
14SU2
Status
affected
Version
12.5(1)SU7
Status
affected
Version
12.5(1)SU7a
Status
affected
Version
14SU3
Status
affected
Version
12.5(1)SU8
Status
affected
Version
12.5(1)SU8a
Status
affected
Version
15
Status
affected
Version
15SU1
Status
affected
Version
14SU4
Status
affected
Version
14SU4a
Status
affected
Version
15SU1a
Status
affected
Version
12.5(1)SU9
Status
affected
Version
15SU2
Status
affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.086 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
psirt@cisco.com | 4.8 | 1.7 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.