Wednesday, July 18, 2018

Multiple Vulnerabilities in Cisco Finesse

Two vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack or retrieve a cleartext password from an affected system.

The vulnerabilities are not dependent on one another; exploitation of one of the vulnerabilities is not required to exploit the other vulnerability. In addition, a software release that is affected by one of the vulnerabilities may not be affected by the other vulnerability.

Details about the vulnerabilities are as follows.

Cisco Finesse HTTP Request Processing Server-Side Request Forgery Vulnerability

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to cause a Cisco Finesse server to submit an HTTP request to an arbitrary host. This type of attack is commonly referred to as a server-side request forgery (SSRF) attack.

The vulnerability is due to insufficient access controls for the Cisco Finesse API that supports gadgets integration. An attacker could exploit this vulnerability by submitting a maliciously crafted HTTP request to a Cisco Finesse server.

The CVE ID for this vulnerability is: CVE-2018-0398

The Security Impact Rating (SIR) for this vulnerability is: Medium

The Common Vulnerability Scoring System (CVSS) Base score for this vulnerability is: 5.8

The Cisco bug ID for this vulnerability is: CSCvg71018

Cisco Finesse Information Disclosure Vulnerability

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to retrieve a cleartext password from an affected system.

The vulnerability exists because the affected software prefills the Password field of the login form for the web-based management interface with a password that was previously saved and is stored in an internal database for the affected software. An attacker could exploit this vulnerability by viewing the HTML source of a login form for the web-based management interface of the affected software. A successful exploit could allow the attacker to view and retrieve a cleartext password from an affected system.

The CVE ID for this vulnerability is: CVE-2018-0399

The SIR for this vulnerability is: Medium

The CVSS Base score for this vulnerability is: 5.3

The Cisco bug ID for this vulnerability is: CSCvg71044



from Cisco Security Advisory https://ift.tt/2O0Fe1w

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.