First published: Wed Jul 18 2018(Updated: )
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. Cisco Bug IDs: CSCvg70921.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Contact Center Express | =11.5\(1\) | |
Cisco Unified IP Interactive Voice Response | =11.5\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-0402 is high.
CVE-2018-0402 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack.
An attacker can exploit CVE-2018-0402 by tricking a user into visiting a malicious website or clicking on a malicious link.
Yes, Cisco has released a security advisory with fixes and mitigations for CVE-2018-0402.
You can find more information about CVE-2018-0402 in the security advisory published by Cisco.