Vulnerability Details CVE-2018-15434
A vulnerability in the web-based management interface of Cisco Unified IP Phone 7900 Series could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 54.3%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2018-15434
-
cpe:2.3:h:cisco:unified_ip_phones_7906g:*
-
cpe:2.3:h:cisco:unified_ip_phones_7911g:*
-
cpe:2.3:h:cisco:unified_ip_phones_7912g:*
-
cpe:2.3:h:cisco:unified_ip_phones_7920_multi-charger:*
-
cpe:2.3:h:cisco:unified_ip_phones_7921g:*
-
cpe:2.3:h:cisco:unified_ip_phones_7925g-ex:*
-
cpe:2.3:h:cisco:unified_ip_phones_7925g:*
-
cpe:2.3:h:cisco:unified_ip_phones_7926g:*
-
cpe:2.3:h:cisco:unified_ip_phones_7931g:*
-
cpe:2.3:h:cisco:unified_ip_phones_7940g:*
-
cpe:2.3:h:cisco:unified_ip_phones_7941g:*
-
cpe:2.3:h:cisco:unified_ip_phones_7942g:*
-
cpe:2.3:h:cisco:unified_ip_phones_7945g:*
-
cpe:2.3:h:cisco:unified_ip_phones_7960g:*
-
cpe:2.3:h:cisco:unified_ip_phones_7961g:*
-
cpe:2.3:h:cisco:unified_ip_phones_7962g:*
-
cpe:2.3:h:cisco:unified_ip_phones_7965g:*
-
cpe:2.3:h:cisco:unified_ip_phones_7975g:*
-
cpe:2.3:h:cisco:unified_ip_phones_conference_station_7936:*
-
cpe:2.3:h:cisco:unified_ip_phones_conference_station_7937g:*
-
cpe:2.3:h:cisco:unified_ip_phones_expansion_module_7915:*
-
cpe:2.3:h:cisco:unified_ip_phones_expansion_module_7916:*
-
cpe:2.3:o:cisco:skinny_client_control_protocol_software:9.4(2)