Vulnerability Details CVE-2024-20305
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 17.4%
CVSS Severity
CVSS v3 Score 4.8
Products affected by CVE-2024-20305
-
cpe:2.3:a:cisco:unity_connection:-
-
cpe:2.3:a:cisco:unity_connection:1.1
-
cpe:2.3:a:cisco:unity_connection:1.1(1)
-
cpe:2.3:a:cisco:unity_connection:1.1(1)_es1
-
cpe:2.3:a:cisco:unity_connection:1.1(1)_es12
-
cpe:2.3:a:cisco:unity_connection:1.1(1)_sr1
-
cpe:2.3:a:cisco:unity_connection:1.2
-
cpe:2.3:a:cisco:unity_connection:1.2(1)
-
cpe:2.3:a:cisco:unity_connection:1.2(1)_es65
-
cpe:2.3:a:cisco:unity_connection:1.2(1)sr2
-
cpe:2.3:a:cisco:unity_connection:1.2_base
-
cpe:2.3:a:cisco:unity_connection:10.0.0
-
cpe:2.3:a:cisco:unity_connection:10.0.5
-
cpe:2.3:a:cisco:unity_connection:10.5
-
cpe:2.3:a:cisco:unity_connection:10.5(2)
-
cpe:2.3:a:cisco:unity_connection:10.5(2)su10
-
cpe:2.3:a:cisco:unity_connection:10.5(2.3009)
-
cpe:2.3:a:cisco:unity_connection:10.5_base
-
cpe:2.3:a:cisco:unity_connection:10.5su5
-
cpe:2.3:a:cisco:unity_connection:11.0
-
cpe:2.3:a:cisco:unity_connection:11.0(0.98000.225)
-
cpe:2.3:a:cisco:unity_connection:11.0(0.98000.332)
-
cpe:2.3:a:cisco:unity_connection:11.0_0
-
cpe:2.3:a:cisco:unity_connection:11.5
-
cpe:2.3:a:cisco:unity_connection:11.5(0.199)
-
cpe:2.3:a:cisco:unity_connection:11.5(0.98)
-
cpe:2.3:a:cisco:unity_connection:11.5(1)
-
cpe:2.3:a:cisco:unity_connection:11.5(1)su3
-
cpe:2.3:a:cisco:unity_connection:11.5(1)su8
-
cpe:2.3:a:cisco:unity_connection:11.5(1)su9
-
cpe:2.3:a:cisco:unity_connection:11.5(1.10000.6)
-
cpe:2.3:a:cisco:unity_connection:11.5_base
-
cpe:2.3:a:cisco:unity_connection:11.5su7
-
cpe:2.3:a:cisco:unity_connection:12.0
-
cpe:2.3:a:cisco:unity_connection:12.0(1)
-
cpe:2.3:a:cisco:unity_connection:12.0(1)su4
-
cpe:2.3:a:cisco:unity_connection:12.5
-
cpe:2.3:a:cisco:unity_connection:12.5(1)
-
cpe:2.3:a:cisco:unity_connection:12.5(1)su3
-
cpe:2.3:a:cisco:unity_connection:12.5(1)su6
-
cpe:2.3:a:cisco:unity_connection:12.5(1)su7
-
cpe:2.3:a:cisco:unity_connection:12.5(1)su8
-
cpe:2.3:a:cisco:unity_connection:12.5su2
-
cpe:2.3:a:cisco:unity_connection:14.0
-
cpe:2.3:a:cisco:unity_connection:14su1
-
cpe:2.3:a:cisco:unity_connection:14su2
-
cpe:2.3:a:cisco:unity_connection:14su3
-
cpe:2.3:a:cisco:unity_connection:2.0
-
cpe:2.3:a:cisco:unity_connection:2.0(1)
-
cpe:2.3:a:cisco:unity_connection:2.0_base
-
cpe:2.3:a:cisco:unity_connection:2.1
-
cpe:2.3:a:cisco:unity_connection:2.1(1)
-
cpe:2.3:a:cisco:unity_connection:2.1(2)
-
cpe:2.3:a:cisco:unity_connection:2.1(3)
-
cpe:2.3:a:cisco:unity_connection:2.1(3b)su1
-
cpe:2.3:a:cisco:unity_connection:2.1(4)
-
cpe:2.3:a:cisco:unity_connection:2.1(4)su1
-
cpe:2.3:a:cisco:unity_connection:2.1(4a)
-
cpe:2.3:a:cisco:unity_connection:2.1(4a)su2
-
cpe:2.3:a:cisco:unity_connection:2.1(5)
-
cpe:2.3:a:cisco:unity_connection:2.1(5)su1
-
cpe:2.3:a:cisco:unity_connection:2.1(5)su2
-
cpe:2.3:a:cisco:unity_connection:2.1(5)su3
-
cpe:2.3:a:cisco:unity_connection:2.1_base
-
cpe:2.3:a:cisco:unity_connection:6.1(3b)su1
-
cpe:2.3:a:cisco:unity_connection:7.0
-
cpe:2.3:a:cisco:unity_connection:7.0(2)
-
cpe:2.3:a:cisco:unity_connection:7.0(2a)su2
-
cpe:2.3:a:cisco:unity_connection:7.0(2a)su3
-
cpe:2.3:a:cisco:unity_connection:7.0_base
-
cpe:2.3:a:cisco:unity_connection:7.1
-
cpe:2.3:a:cisco:unity_connection:7.1(1)
-
cpe:2.3:a:cisco:unity_connection:7.1(2)
-
cpe:2.3:a:cisco:unity_connection:7.1(2a)
-
cpe:2.3:a:cisco:unity_connection:7.1(2a)su1
-
cpe:2.3:a:cisco:unity_connection:7.1(2b)
-
cpe:2.3:a:cisco:unity_connection:7.1(2b)su1
-
cpe:2.3:a:cisco:unity_connection:7.1(3)
-
cpe:2.3:a:cisco:unity_connection:7.1(3a)
-
cpe:2.3:a:cisco:unity_connection:7.1(3a)su1
-
cpe:2.3:a:cisco:unity_connection:7.1(3a)su1a
-
cpe:2.3:a:cisco:unity_connection:7.1(3b)
-
cpe:2.3:a:cisco:unity_connection:7.1(3b)su1
-
cpe:2.3:a:cisco:unity_connection:7.1(3b)su2
-
cpe:2.3:a:cisco:unity_connection:7.1(5)
-
cpe:2.3:a:cisco:unity_connection:7.1(5)su1a
-
cpe:2.3:a:cisco:unity_connection:7.1(5a)
-
cpe:2.3:a:cisco:unity_connection:7.1(5b)
-
cpe:2.3:a:cisco:unity_connection:7.1(5b)su2
-
cpe:2.3:a:cisco:unity_connection:7.1(5b)su3
-
cpe:2.3:a:cisco:unity_connection:7.1(5b)su4
-
cpe:2.3:a:cisco:unity_connection:7.1(5b)su5
-
cpe:2.3:a:cisco:unity_connection:7.1(5b)su6
-
cpe:2.3:a:cisco:unity_connection:7.1(5b)su6a
-
cpe:2.3:a:cisco:unity_connection:7.1.5es33.32900-33
-
cpe:2.3:a:cisco:unity_connection:7.1_base
-
cpe:2.3:a:cisco:unity_connection:8.0
-
cpe:2.3:a:cisco:unity_connection:8.0(2c)
-
cpe:2.3:a:cisco:unity_connection:8.0(2c)su1
-
cpe:2.3:a:cisco:unity_connection:8.0(3)
-
cpe:2.3:a:cisco:unity_connection:8.0(3a)
-
cpe:2.3:a:cisco:unity_connection:8.0(3a)su1
-
cpe:2.3:a:cisco:unity_connection:8.0(3a)su2
-
cpe:2.3:a:cisco:unity_connection:8.0(3a)su3
-
cpe:2.3:a:cisco:unity_connection:8.0_base
-
cpe:2.3:a:cisco:unity_connection:8.5
-
cpe:2.3:a:cisco:unity_connection:8.5(1)
-
cpe:2.3:a:cisco:unity_connection:8.5(1)su1
-
cpe:2.3:a:cisco:unity_connection:8.5(1)su2
-
cpe:2.3:a:cisco:unity_connection:8.5(1)su3
-
cpe:2.3:a:cisco:unity_connection:8.5(1)su6
-
cpe:2.3:a:cisco:unity_connection:8.5_base
-
cpe:2.3:a:cisco:unity_connection:8.6
-
cpe:2.3:a:cisco:unity_connection:8.6(1a)
-
cpe:2.3:a:cisco:unity_connection:8.6(2a)
-
cpe:2.3:a:cisco:unity_connection:8.6.2
-
cpe:2.3:a:cisco:unity_connection:8.6_base
-
cpe:2.3:a:cisco:unity_connection:9.0
-
cpe:2.3:a:cisco:unity_connection:9.1(1)es23
-
cpe:2.3:a:cisco:unity_connection:9.1(1.10)
-
cpe:2.3:a:cisco:unity_connection:9.5