Information disclosure in Unified Communications Manager (CallManager) - CVE-2016-6440
Published: October 12, 2016 / Updated: April 5, 2018
Vulnerability identifier: #VU938
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2016-6440
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Cisco Systems, Inc
Affected software:
Unified Communications Manager (CallManager)
Unified Communications Manager (CallManager)
Detailed vulnerability description
The vulnerability allows a remote unauthenticated user to hijack important information on the target system.
The weakness is due to insufficient input sanitization of iframe data within the HTTP requests sent to the device. By sending a specially crafted HTTP packets with malicious iframe data and tricking the victim to click on a malicious link, attackers can conduct clickjacking or phishing attack.
Successful exploitation of the vulnerability will result in disclosure of valid user's credentials.
The weakness is due to insufficient input sanitization of iframe data within the HTTP requests sent to the device. By sending a specially crafted HTTP packets with malicious iframe data and tricking the victim to click on a malicious link, attackers can conduct clickjacking or phishing attack.
Successful exploitation of the vulnerability will result in disclosure of valid user's credentials.
How to mitigate CVE-2016-6440
Update fixed versions:
11.5(0.98000.1070);
11.5(0.98000.284);
11.5(0.98000.346);
11.5(0.98000.768);
11.5(1.10000.3);
11.5(1.10000.6);
11.5(2.10000.2).
11.5(0.98000.1070);
11.5(0.98000.284);
11.5(0.98000.346);
11.5(0.98000.768);
11.5(1.10000.3);
11.5(1.10000.6);
11.5(2.10000.2).