CVE-2017-3802: Cisco Unified Communications Manager

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCvc20679. Known Affected Releases: 12.0(0.99000.9). Known Fixed Releases: 12.0(0.98000.176) 12.0(0.98000.414) 12.0(0.98000.531) 12.0(0.98000.536) 12.0(0.98000.6) 12.0(0.98500.8).

Affected products

  • Cisco Unified Communications Manager: version 12.0(0.99000.9) only

Published 2017-01-26. Last modified 2026-06-17.