A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected system. This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated to the affected device.
2024-06-05T17:15:11.790
2024-11-21T08:52:33.903
Modified
CVSSv3.1: 7.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cisco | finesse | < 11.6\(1\) | Yes |
Application | cisco | finesse | 11.6\(1\) | Yes |
Application | cisco | finesse | 11.6\(1\) | Yes |
Application | cisco | finesse | 11.6\(1\) | Yes |
Application | cisco | finesse | 11.6\(1\) | Yes |
Application | cisco | finesse | 11.6\(1\) | Yes |
Application | cisco | finesse | 11.6\(1\) | Yes |
Application | cisco | finesse | 12.6\(2\) | Yes |
Application | cisco | finesse | 12.6\(2\) | Yes |
Application | cisco | finesse | 12.6\(2\) | Yes |