First published: Fri Apr 04 2014(Updated: )
Multiple open redirect vulnerabilities in Cisco Emergency Responder (ER) 8.6 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified parameters, aka Bug ID CSCun37909.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Emergency Responder | <=8.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2117 has been rated as medium severity due to its potential for allowing phishing attacks.
To fix CVE-2014-2117, users should upgrade to a version of Cisco Emergency Responder that is later than 8.6.
CVE-2014-2117 affects Cisco Emergency Responder versions 8.6 and earlier.
CVE-2014-2117 can enable remote attackers to conduct phishing attacks via open redirect vulnerabilities.
There are no specific workarounds available for CVE-2014-2117; upgrading the software is the recommended action.