SB2016101206 - Information disclosure in Cisco Unified Communications Manager
Published: October 12, 2016 Updated: April 5, 2018
Security Bulletin ID
SB2016101206
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2016-6440)
The vulnerability allows a remote unauthenticated user to hijack important information on the target system.
The weakness is due to insufficient input sanitization of iframe data within the HTTP requests sent to the device. By sending a specially crafted HTTP packets with malicious iframe data and tricking the victim to click on a malicious link, attackers can conduct clickjacking or phishing attack.
Successful exploitation of the vulnerability will result in disclosure of valid user's credentials.
The weakness is due to insufficient input sanitization of iframe data within the HTTP requests sent to the device. By sending a specially crafted HTTP packets with malicious iframe data and tricking the victim to click on a malicious link, attackers can conduct clickjacking or phishing attack.
Successful exploitation of the vulnerability will result in disclosure of valid user's credentials.
Remediation
Install update from vendor's website.