Lucene search

K
ciscoCiscoCISCO-SA-FINESSE-SSRF-RFI-UM7WT8EW
HistoryJun 05, 2024 - 4:00 p.m.

Cisco Finesse Web-Based Management Interface Vulnerabilities

2024-06-0516:00:00
tools.cisco.com
8
cisco finesse
web-based
management interface
vulnerabilities
remote attacker
cross site-scripting
remote file inclusion
server-side request forgery
advisory
software updates

5.9 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.1%

Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to perform a stored cross site-scripting (XSS) attack by exploiting a remote file inclusion (RFI) vulnerability or perform a server-side request forgery (SSRF) attack an affected system.

For more information about these vulnerabilities, see the Details [“#details”] section of this advisory.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-ssrf-rfi-Um7wT8Ew [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-ssrf-rfi-Um7wT8Ew”]

Affected configurations

Vulners
Node
ciscounified_contact_center_enterpriseMatchany
OR
ciscounified_contact_center_expressMatchany
OR
ciscofinesseMatchany
OR
ciscopackaged_contact_center_enterpriseMatchany
OR
ciscounified_contact_center_enterpriseMatchany
OR
ciscounified_contact_center_expressMatchany
OR
ciscofinesseMatchany
OR
ciscopackaged_contact_center_enterpriseMatchany

5.9 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.1%

Related for CISCO-SA-FINESSE-SSRF-RFI-UM7WT8EW