CVE-2018-0398: SSRF
Published Jul 18, 2018
·Updated
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack. Cisco Bug IDs: CSCvg71018.
Affected Software
1 affected component
Cisco Finesse=11.5\(1\)
Event History
Jul 18, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-0398?
CVE-2018-0398 is considered a high severity vulnerability due to its potential for server-side request forgery attacks.
2
What impact does CVE-2018-0398 have on Cisco Finesse?
CVE-2018-0398 allows unauthenticated remote attackers to exploit vulnerabilities in the web-based management interface of Cisco Finesse.
3
How do I fix CVE-2018-0398?
To mitigate CVE-2018-0398, you should apply the security patches provided by Cisco for the affected version of Finesse.
4
Which versions of Cisco Finesse are affected by CVE-2018-0398?
CVE-2018-0398 specifically affects Cisco Finesse version 11.5(1).
5
Can CVE-2018-0398 be exploited remotely?
Yes, CVE-2018-0398 can be exploited by remote attackers without authentication.