CVE-2013-3455: Medium severity Cisco Finesse vulnerability
Published Aug 12, 2013
·Updated
Cisco Finesse allows remote attackers to obtain sensitive information by sniffing the network for HTTP query data, aka Bug ID CSCug16732.
Affected Software
1 affected component
Cisco Finesse
Event History
Aug 12, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3455?
CVE-2013-3455 has a medium severity rating due to its potential for sensitive information disclosure through network sniffing.
2
How do I fix CVE-2013-3455?
To mitigate CVE-2013-3455, ensure that sensitive data is transmitted over secure channels, such as HTTPS.
3
What type of attack does CVE-2013-3455 involve?
CVE-2013-3455 involves a remote information disclosure attack that allows attackers to sniff HTTP query data.
4
Which software is affected by CVE-2013-3455?
CVE-2013-3455 affects Cisco Finesse versions that do not implement proper encryption for HTTP traffic.
5
Can CVE-2013-3455 be exploited remotely?
Yes, CVE-2013-3455 can be exploited remotely by attackers who have access to the same network.