CVE-2017-6757

8.8 HIGH
Published: August 07, 2017 Modified: May 13, 2026
View on NVD

Description

A vulnerability in Cisco Unified Communications Manager 10.5(2.10000.5), 11.0(1.10000.10), and 11.5(1.10000.6) could allow an authenticated, remote attacker to conduct a blind SQL injection attack. The vulnerability is due to a failure to validate user-supplied input used in SQL queries that bypass protection filters. An attacker could exploit this vulnerability by sending crafted URLs that include SQL statements. An exploit could allow the attacker to modify or delete entries in some database tables, affecting the integrity of the data. Cisco Bug IDs: CSCve13786.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://www.securityfocus.com/bid/100121
Source: psirt@cisco.com
Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1039063
Source: psirt@cisco.com
Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/100121
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1039063
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
https://quickview.cloudapps.cisco.com/quickview/bug/CSCve13786
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

8 reference(s) from NVD

Quick Stats

CVSS v3 Score
8.8 / 10.0
EPSS (Exploit Probability)
1.6%
73th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

cisco