CVE-2015-4206 describes a cross-site scripting (XSS) vulnerability in Cisco Unified Communications Manager (UCM) versions 8.0 through 8.6, allowing remote attackers to bypass an XSS protection mechanism through a crafted parameter. This vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and potential for partial integrity impact, with no confidentiality or availability impact. There is no evidence of active exploitation, no public exploit code available (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage. The vulnerability is considered inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0\(2c\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:8.0\(2c\):*:*:*:*:*:*:* | ||
8.0\(3\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:8.0\(3\):*:*:*:*:*:*:* | ||
8.0_baseCPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:8.0_base:*:*:*:*:*:*:* | ||
8.5.1CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:8.5.1:*:*:*:*:*:*:* | ||
8.5_baseCPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:8.5_base:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.