CVE-2015-0754
published 2015-05-29CVE-2015-0754: Cisco Finesse 10.5(1) allows remote authenticated users to obtain sensitive information or cause a denial of service (CPU and memory consumption) via a crafted…
PriorityP433high7.5CVSS 2.0
AVNACLAuSCPINAC
EPSS
1.94%
77.8th percentile
Cisco Finesse 10.5(1) allows remote authenticated users to obtain sensitive information or cause a denial of service (CPU and memory consumption) via a crafted XML document, aka Bug ID CSCut95810.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | finesse | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:S/C:P/I:N/A:C
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Finesse XML Processing Denial of Service Vulnerability
vendor_cisco·2015-05-27·CVSS 7.5
CVE-2015-0754 [HIGH] CWE-20 Cisco Finesse XML Processing Denial of Service Vulnerability
Cisco Finesse XML Processing Denial of Service Vulnerability
A vulnerability in Cisco Finesse could allow an authenticated, remote attacker to gain access to sensitive information or cause a denial of service (DoS) condition.
The vulnerability is due to improper processing of XML files by an affected device. An authenticated, remote attacker could exploit this vulnerability by sending a malicious XML file to the affected device. Processing the malicious XML file could cause the device to consume excessive amounts of CPU and memory resources that could trigger a DoS condition. The attacker could also gain access to sensitive information on the device, which could be leveraged to conduct further attacks.
Cisco has confirmed the vulnerability; however, software updates are not available.
GHSA
GHSA-gffc-hhrm-xfv2: Cisco Finesse 10
ghsa_unreviewed·2022-05-17
CVE-2015-0754 [HIGH] CWE-20 GHSA-gffc-hhrm-xfv2: Cisco Finesse 10
Cisco Finesse 10.5(1) allows remote authenticated users to obtain sensitive information or cause a denial of service (CPU and memory consumption) via a crafted XML document, aka Bug ID CSCut95810.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-05-29
Published