First published: Wed Jul 18 2018(Updated: )
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to retrieve a cleartext password from an affected system. Cisco Bug IDs: CSCvg71044.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Finesse | =11.5\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-0399 is critical with a CVSS score of 9.8.
The affected software is Cisco Finesse version 11.5(1).
An unauthenticated attacker can exploit CVE-2018-0399 by retrieving a cleartext password from an affected system.
Yes, Cisco has released a security advisory with fixes for CVE-2018-0399.
The Common Weakness Enumerations (CWEs) associated with CVE-2018-0399 are CWE-918 and CWE-264.