CVE-2017-6670
Last modified
CVE-2017-6670 is a vulnerability of currently unknown severity. A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect issue. More Information: CSCvc54813. EPSS estimates a 1.20% chance of exploitation in the next 30 days.
Description
A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect issue. More Information: CSCvc54813. Known Affected Releases: 8.1(7)ER1.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Communications Domain Manager | 8.1\(7\)er1 |
References
- http://www.securityfocus.com/bid/98946Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/98946Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-6670?
How severe is CVE-2017-6670?
How do I fix CVE-2017-6670?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-6664A vulnerability in the Autonomic Networking feature of Cisco…
- CVE-2017-6665A vulnerability in the Autonomic Networking feature of Cisco…6.5
- CVE-2017-6666A vulnerability in the forwarding component of Cisco IOS XR …
- CVE-2017-6667A vulnerability in the update process for the dynamic JAR fi…
- CVE-2017-6668Vulnerabilities in the web-based GUI of Cisco Unified Commun…
- CVE-2017-6669Multiple buffer overflow vulnerabilities exist in the Cisco …7.8
- CVE-2017-6671A vulnerability in the email message scanning of Cisco Async…
- CVE-2017-6672A vulnerability in certain filtering mechanisms of access co…
- CVE-2017-6673A vulnerability in Cisco Firepower Management Center could a…
- CVE-2017-6674A vulnerability in the feature-license management functional…
- CVE-2017-6675A vulnerability in the web interface of Cisco Industrial Net…
- CVE-2017-6678A vulnerability in the ingress UDP packet processing functio…
Are you affected by CVE-2017-6670?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
