Lucene search

K
cveCiscoCVE-2016-1373
HistoryMay 05, 2016 - 9:59 p.m.

CVE-2016-1373

2016-05-0521:59:03
cisco
web.nvd.nist.gov
30
cisco
finesse
api
ssrf
vulnerability
cve-2016-1373
security
cisco finesse

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

AI Score

8.4

Confidence

High

EPSS

0.002

Percentile

53.1%

The gadgets-integration API in Cisco Finesse 8.5(1) through 8.5(5), 8.6(1), 9.0(1), 9.0(2), 9.1(1), 9.1(1)SU1, 9.1(1)SU1.1, 9.1(1)ES1 through 9.1(1)ES5, 10.0(1), 10.0(1)SU1, 10.0(1)SU1.1, 10.5(1), 10.5(1)ES1 through 10.5(1)ES4, 10.5(1)SU1, 10.5(1)SU1.1, 10.5(1)SU1.7, 10.6(1), 10.6(1)SU1, 10.6(1)SU2, and 11.0(1) allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted request, aka Bug ID CSCuw86623.

Affected configurations

Nvd
Node
ciscofinesseMatch8.5\(1\)_base
OR
ciscofinesseMatch8.5\(2\)_base
OR
ciscofinesseMatch8.5\(3\)_base
OR
ciscofinesseMatch8.5\(4\)_base
OR
ciscofinesseMatch8.5\(5\)_base
OR
ciscofinesseMatch8.6\(1\)_base
OR
ciscofinesseMatch9.0\(1\)_base
OR
ciscofinesseMatch9.0\(2\)_base
OR
ciscofinesseMatch9.1\(1\)_base
OR
ciscofinesseMatch9.1\(1\)_es1
OR
ciscofinesseMatch9.1\(1\)_es2
OR
ciscofinesseMatch9.1\(1\)_es3
OR
ciscofinesseMatch9.1\(1\)_es4
OR
ciscofinesseMatch9.1\(1\)_es5
OR
ciscofinesseMatch9.1\(1\)_su1
OR
ciscofinesseMatch9.1\(1\)_su1.1
OR
ciscofinesseMatch10.0\(1\)_base
OR
ciscofinesseMatch10.0\(1\)_su1
OR
ciscofinesseMatch10.0\(1\)_su1.1
OR
ciscofinesseMatch10.5\(1\)_base
OR
ciscofinesseMatch10.5\(1\)_es1
OR
ciscofinesseMatch10.5\(1\)_es2
OR
ciscofinesseMatch10.5\(1\)_es3
OR
ciscofinesseMatch10.5\(1\)_es4
OR
ciscofinesseMatch10.5\(1\)_su1
OR
ciscofinesseMatch10.5\(1\)_su1.1
OR
ciscofinesseMatch10.5\(1\)_su1.7
OR
ciscofinesseMatch10.6\(1\)_base
OR
ciscofinesseMatch10.6\(1\)_su1
OR
ciscofinesseMatch10.6\(1\)_su2
OR
ciscofinesseMatch11.0\(1\)_base
VendorProductVersionCPE
ciscofinesse8.5(1)_basecpe:2.3:a:cisco:finesse:8.5\(1\)_base:*:*:*:*:*:*:*
ciscofinesse8.5(2)_basecpe:2.3:a:cisco:finesse:8.5\(2\)_base:*:*:*:*:*:*:*
ciscofinesse8.5(3)_basecpe:2.3:a:cisco:finesse:8.5\(3\)_base:*:*:*:*:*:*:*
ciscofinesse8.5(4)_basecpe:2.3:a:cisco:finesse:8.5\(4\)_base:*:*:*:*:*:*:*
ciscofinesse8.5(5)_basecpe:2.3:a:cisco:finesse:8.5\(5\)_base:*:*:*:*:*:*:*
ciscofinesse8.6(1)_basecpe:2.3:a:cisco:finesse:8.6\(1\)_base:*:*:*:*:*:*:*
ciscofinesse9.0(1)_basecpe:2.3:a:cisco:finesse:9.0\(1\)_base:*:*:*:*:*:*:*
ciscofinesse9.0(2)_basecpe:2.3:a:cisco:finesse:9.0\(2\)_base:*:*:*:*:*:*:*
ciscofinesse9.1(1)_basecpe:2.3:a:cisco:finesse:9.1\(1\)_base:*:*:*:*:*:*:*
ciscofinesse9.1(1)_es1cpe:2.3:a:cisco:finesse:9.1\(1\)_es1:*:*:*:*:*:*:*
Rows per page:
1-10 of 311

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

AI Score

8.4

Confidence

High

EPSS

0.002

Percentile

53.1%

Related for CVE-2016-1373