Two vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack or retrieve a cleartext password from an affected system.
The vulnerabilities are not dependent on one another; exploitation of one of the vulnerabilities is not required to exploit the other vulnerability. In addition, a software release that is affected by one of the vulnerabilities may not be affected by the other vulnerability.
Details about the vulnerabilities are as follows.
Cisco Finesse HTTP Request Processing Server-Side Request Forgery Vulnerability
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to cause a Cisco Finesse server to submit an HTTP request to an arbitrary host. This type of attack is commonly referred to as a server-side request forgery (SSRF) attack.
The vulnerability is due to insufficient access controls for the Cisco Finesse API that supports gadgets integration. An attacker could exploit this vulnerability by submitting a maliciously crafted HTTP request to a Cisco Finesse server.
The CVE ID for this vulnerability is: CVE-2018-0398
The Security Impact Rating (SIR) for this vulnerability is: Medium
The Common Vulnerability Scoring System (CVSS) Base score for this vulnerability is: 5.8
The Cisco bug ID for this vulnerability is: CSCvg71018
Cisco Finesse Information Disclosure Vulnerability
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to retrieve a cleartext password from an affected system.
The vulnerability exists because the affected software prefills the Password field of the login form for the web-based management interface with a password that was previously saved and is stored in an internal database for the affected software. An attacker could exploit this vulnerability by viewing the HTML source of a login form for the web-based management interface of the affected software. A successful exploit could allow the attacker to view and retrieve a cleartext password from an affected system.
The CVE ID for this vulnerability is: CVE-2018-0399
The SIR for this vulnerability is: Medium
The CVSS Base score for this vulnerability is: 5.3
The Cisco bug ID for this vulnerability is: CSCvg71044
from Cisco Security Advisory https://ift.tt/2O0Fe1w
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.