First published: Mon Aug 12 2013(Updated: )
Cisco Finesse allows remote attackers to obtain sensitive information by sniffing the network for HTTP query data, aka Bug ID CSCug16732.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Finesse |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3455 has a medium severity rating due to its potential for sensitive information disclosure through network sniffing.
To mitigate CVE-2013-3455, ensure that sensitive data is transmitted over secure channels, such as HTTPS.
CVE-2013-3455 involves a remote information disclosure attack that allows attackers to sniff HTTP query data.
CVE-2013-3455 affects Cisco Finesse versions that do not implement proper encryption for HTTP traffic.
Yes, CVE-2013-3455 can be exploited remotely by attackers who have access to the same network.