← Vulnerability feed

Vulnerability record · CVE-2018-15434 · published 5 October 2018

CVE-2018-15434: Cisco skinny client control protocol software cross-site scripting vulnerability

Cisco · Skinny Client Control Protocol Software

A vulnerability in the web-based management interface of Cisco Unified IP Phone 7900 Series could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

6.1 CVSS 3.0 Medium EPSS 0.92% · top 41.3% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
0.92%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the web-based management interface of Cisco Unified IP Phone 7900 Series could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-15434 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.8CVE-2012-5445Cisco skinny client control protocol software improper input validation vulnerabilityThe kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properl…EPSS 0.40%6.6CVE-2011-1602Cisco unified ip phone 7906 permissions and access controls vulnerabilityThe su utility on Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.0.3 allows local users to gain privileges via unspecif…EPSS 0.26%6.6CVE-2011-1603Cisco unified ip phone 7906 permissions and access controls vulnerabilityCisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 allow local users to gain privileges via unspecified vectors, aka Bu…EPSS 0.26%6.4CVE-2002-0882Cisco voip phone cp-7940 vulnerabilityThe web server for Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allows remote attackers to cause a denial of service (reset) and possibly read s…EPSS 2.7%5.0CVE-2002-0880Cisco voip phone cp-7940 vulnerabilityCisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated b…EPSS 1.3%2.1CVE-2002-0881Cisco voip phone cp-7940 vulnerabilityCisco IP Phone (VoIP) models 7910, 7940, and 7960 use a default administrative password, which allows attackers with physical access to the phone to …EPSS 0.39%1.5CVE-2011-1637Cisco unified ip phone 7906 permissions and access controls vulnerabilityCisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 do not properly verify signatures for software images, which allows …EPSS 0.27%6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed

Source: NIST National Vulnerability Database (record CVE-2018-15434), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.