CVE-2015-0754

Severity
7.5HIGH
EPSS
0.3%
top 42.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 29
Latest updateMay 17

Description

Cisco Finesse 10.5(1) allows remote authenticated users to obtain sensitive information or cause a denial of service (CPU and memory consumption) via a crafted XML document, aka Bug ID CSCut95810.

CVSS vector

AV:N/AC:L/C:P/I:N/A:CExploitability: 8.0 | Impact: 7.8

Affected Packages1 packages

NVDcisco/finesse10.5\(1\)_base

🔴Vulnerability Details

2
GHSA
GHSA-gffc-hhrm-xfv2: Cisco Finesse 102022-05-17
CVEList
CVE-2015-0754: Cisco Finesse 102015-05-29

📋Vendor Advisories

1
Cisco
Cisco Finesse XML Processing Denial of Service Vulnerability2015-05-27
CVE-2015-0754 (HIGH CVSS 7.5) | Cisco Finesse 10.5(1) allows remote | cvebase.io