CVE-2018-0445: Cisco Packaged Contact Center Enterprise Cross-Site Request Forgery Vulnerability
A vulnerability in the web-based management interface of Cisco Packaged Contact Center Enterprise could allow an unauthenticated, remote attacker to conduct a CSRF attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a customized link. A successful exploit could allow the attacker to perform arbitrary actions on a targeted device via a web browser and with the privileges of the user.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-0445.
What is the severity of CVE-2018-0445?
The severity of CVE-2018-0445 is high with a CVSS score of 8.8.
What software is affected by CVE-2018-0445?
Cisco Packaged Contact Center Enterprise version 11.6(1) is affected by CVE-2018-0445.
How can an attacker exploit CVE-2018-0445?
An attacker can exploit CVE-2018-0445 by conducting a CSRF attack on the web-based management interface of the affected device.
Is there a fix available for CVE-2018-0445?
Yes, Cisco has released a security advisory with mitigation details for CVE-2018-0445. Please refer to the provided reference link for more information on the fix.