VDB

CVE-2017-3886

CVE-2017-3886 PUBLISHED CVSS 4.900000095367432 MEDIUM

A vulnerability in the Cisco Unified Communications Manager web interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. The attacker must be authenticated as an administrative user to execute SQL database queries. More Information: CSCvc74291. Known Affected Releases: 1.0(1.10000.10) 11.5(1.10000.6). Known Fixed Releases: 12.0(0.98000.619) 12.0(0.98000.485) 12.0(0.98000.212) 11.5(1.13035.1) 11.0(1.23900.5) 11.0(1.23900.2) 11.0(1.23067.1) 10.5(2.15900.2).

EPSS 1.88% · 78.0th percentile

Risk Scores

CVSS 3.0
4.900000095367432
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS Score
1.88%
78.0th percentile

Affected Products

VendorProductVersions
n/aCisco Unified Communications ManagerCisco Unified Communications Manager
ciscounified_communications_manager11.0\(1.10000.10\), 11.5\(1.10000.6\)

Timeline

  • Apr 5, 2017 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 28, 2021 EPSS Score
  • Mar 1, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 4, 2022 EPSS Score
  • Nov 8, 2022 EPSS Score
  • Jan 9, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›