CVE-2017-3829: Cisco Unified Communications Manager

Medium severity, CVSS 6.1. EPSS: 1.5% chance of exploitation in the next 30 days.

A vulnerability in the web-based management interface of Cisco Unified Communications Manager Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvc30999. Known Affected Releases: 12.0(0.98000.280). Known Fixed Releases: 11.0(1.23900.3) 12.0(0.98000.180) 12.0(0.98000.422) 12.0(0.98000.541) 12.0(0.98000.6).

Affected products

  • Cisco Unified Communications Manager: version 11.0(1.10000.10) only; version 11.5(1.10000.6) only

Published 2017-02-22. Last modified 2026-06-17.