Vulnerability Details CVE-2017-6722
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated, remote attacker to masquerade as a legitimate user, aka a Clear Text Authentication Vulnerability. More Information: CSCuw86638. Known Affected Releases: 10.6(1). Known Fixed Releases: 11.5(1.10000.61).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 62.4%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 5.5
Products affected by CVE-2017-6722
-
cpe:2.3:a:cisco:unified_contact_center_express:11.5(1)
-
cpe:2.3:a:cisco:unified_contact_center_express:11.5.1es01
-
cpe:2.3:a:cisco:unified_contact_center_express:11.5.1su1