cisco-sa-20180718-finesse: Multiple Vulnerabilities in Cisco Finesse
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack or retrieve a cleartext password from an affected system. For more information about these vulnerabilities, see the Details section of this security advisory. There are no workarounds that address these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180718-finesse
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0366 in cisco-sa-20180718-finesse?
The severity of CVE-2018-0366 is classified as critical due to its ability to allow unauthenticated remote attackers to conduct SSRF attacks.
How do I fix CVE-2018-0366 in cisco-sa-20180718-finesse?
To fix CVE-2018-0366, upgrade to the latest version of Cisco Finesse as recommended in the security advisory.
What kind of attacks can be executed due to the vulnerabilities in cisco-sa-20180718-finesse?
The vulnerabilities in cisco-sa-20180718-finesse can enable server-side request forgery attacks and compromise user credentials.
Is Cisco Finesse affected by CVE-2018-0365 mentioned in cisco-sa-20180718-finesse?
Yes, Cisco Finesse is affected by CVE-2018-0365, which concerns the retrieval of cleartext passwords from the system.
Who can exploit the vulnerabilities described in cisco-sa-20180718-finesse?
Unauthenticated remote attackers can exploit the vulnerabilities described in cisco-sa-20180718-finesse.