Vulnerabilities > Cisco > Unified Intelligence Center

DATE CVE VULNERABILITY TITLE RISK
2017-11-16 CVE-2017-12337 Improper Authentication vulnerability in Cisco products
A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an unauthenticated, remote attacker to gain unauthorized, elevated access to an affected device.
network
low complexity
cisco CWE-287
critical
10.0
2017-09-21 CVE-2017-12254 Cross-site Scripting vulnerability in Cisco Unified Intelligence Center 11.5(1)
A vulnerability in the web interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to perform a Document Object Model (DOM)-based cross-site scripting attack.
network
cisco CWE-79
4.3
2017-09-21 CVE-2017-12253 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Unified Intelligence Center 11.5(1)
A vulnerability in the Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to execute unwanted actions.
network
cisco CWE-352
6.8
2017-09-21 CVE-2017-12248 Cross-site Scripting vulnerability in Cisco Unified Intelligence Center 11.5(1)
A vulnerability in the web framework code of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system.
network
cisco CWE-79
4.3
2017-09-07 CVE-2017-6789 Cross-site Scripting vulnerability in Cisco Unified Intelligence Center 11.0(1)Es10
A vulnerability in the Cisco Unified Intelligence Center web interface could allow an unauthenticated, remote attacker to impact the integrity of the system by executing a Document Object Model (DOM)-based, environment or client-side cross-site scripting (XSS) attack.
network
cisco CWE-79
4.3
2016-10-06 CVE-2016-6427 Cross-Site Request Forgery (CSRF) vulnerability in Cisco products
Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuy75036 and CSCuy81654.
network
cisco CWE-352
6.8
2016-10-06 CVE-2016-6425 Cross-site Scripting vulnerability in Cisco products
Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCuy75020 and CSCuy81652.
network
cisco CWE-79
4.3
2016-10-05 CVE-2016-6426 Improper Input Validation vulnerability in Cisco products
The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to create user accounts by visiting an unspecified web page, aka Bug IDs CSCuy75027 and CSCuy81653.
network
cisco CWE-20
4.3
2015-07-16 CVE-2015-4274 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Unified Intelligence Center 10.0(1)/10.6(1)
Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Unified Intelligence Center 10.0(1) and 10.6(1) allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuu94862 and CSCuu97936.
network
cisco CWE-352
6.8
2015-05-20 CVE-2015-0740 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Unified Intelligence Center 10.6(1)
Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center 10.6(1) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCus28826.
network
cisco CWE-352
6.8