CVE-2018-15403 is an open redirect vulnerability affecting the web interfaces of Cisco Emergency Responder, Cisco Unified Communications Manager, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection. An authenticated, remote attacker can exploit improper input validation in HTTP request parameters to redirect users to malicious web pages, facilitating phishing attacks. Rated Medium (CVSS 5.4), the attack requires user interaction and authenticated access, with potential impacts on confidentiality and integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.5\(2.10000.5\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:10.5\(2.10000.5\):*:*:*:*:*:*:* | ||
11.0\(1.10000.10\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:11.0\(1.10000.10\):*:*:*:*:*:*:* | ||
11.5\(1.10000.6\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:11.5\(1.10000.6\):*:*:*:*:*:*:* | ||
12.0\(1.10000.10\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:12.0\(1.10000.10\):*:*:*:*:*:*:* | ||
9.1\(1\)es23CPE matchmatch criteria | cpe:2.3:a:cisco:unity_connection:9.1\(1\)es23:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.