AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-3886

MEDIUM · CVSS 4.9 EPSS 1.88%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-04-07 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.9. It affects Cisco. It may be remotely exploitable. It involves a SQL injection risk.

CVE
CVE-2017-3886
Severity
MEDIUM
CVSS
4.9
EPSS
1.88%
Cisco

Original NVD Description

A vulnerability in the Cisco Unified Communications Manager web interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. The attacker must be authenticated as an administrative user to execute SQL database queries. More Information: CSCvc74291. Known Affected Releases: 1.0(1.10000.10) 11.5(1.10000.6). Known Fixed Releases: 12.0(0.98000.619) 12.0(0.98000.485) 12.0(0.98000.212) 11.5(1.13035.1) 11.0(1.23900.5) 11.0(1.23900.2) 11.0(1.23067.1) 10.5(2.15900.2).

Related CVEs

Other vulnerabilities affecting the same vendor(s)