CVE-2018-0399: SSRF
Published Jul 18, 2018
·Updated
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to retrieve a cleartext password from an affected system. Cisco Bug IDs: CSCvg71044.
Affected Software
1 affected component
Cisco Finesse=11.5\(1\)
Event History
Jul 18, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-0399?
The severity of CVE-2018-0399 is critical with a CVSS score of 9.8.
2
What is the affected software by CVE-2018-0399?
The affected software is Cisco Finesse version 11.5(1).
3
How can an unauthenticated attacker exploit CVE-2018-0399?
An unauthenticated attacker can exploit CVE-2018-0399 by retrieving a cleartext password from an affected system.
4
Are there any known fixes for CVE-2018-0399?
Yes, Cisco has released a security advisory with fixes for CVE-2018-0399.
5
What are the Common Weakness Enumerations (CWEs) associated with CVE-2018-0399?
The Common Weakness Enumerations (CWEs) associated with CVE-2018-0399 are CWE-918 and CWE-264.