CVE-2016-1307
published 2016-02-07CVE-2016-1307: The Openfire server in Cisco Finesse Desktop 10.5(1) and 11.0(1) and Unified Contact Center Express 10.6(1) has a hardcoded account, which makes it easier for…
PriorityP429medium5.4CVSS 3.0
AVNACLPRLUINSUCLILAN
EPSS
1.13%
63.2th percentile
The Openfire server in Cisco Finesse Desktop 10.5(1) and 11.0(1) and Unified Contact Center Express 10.6(1) has a hardcoded account, which makes it easier for remote attackers to obtain access via an XMPP session, aka Bug ID CSCuw79085.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | finesse_desktop_and_cisco_unified_contact_center_express_applications_xmpp_unaut | — | — |
| zyxel | gs1900-10hp_firmware | < 2.50\(aazi.0\)c0 | 2.50\(aazi.0\)c0 |
| zzinc | keymouse_firmware | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
vendor_cisco6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Finesse Desktop and Cisco Unified Contact Center Express Applications XMPP Unauthorized Access Vulnerability
vendor_cisco·2016-02-02·CVSS 6.4
CVE-2016-1307 [MEDIUM] CWE-264 Cisco Finesse Desktop and Cisco Unified Contact Center Express Applications XMPP Unauthorized Access Vulnerability
Cisco Finesse Desktop and Cisco Unified Contact Center Express Applications XMPP Unauthorized Access Vulnerability
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) in the Cisco Finesse Desktop and Cisco Unified Contact Center Express applications could allow an unauthenticated, remote attacker to log in to the device with a default account with a static password. This account provides nonadministrative access to the Openfire server bundled with the application.
The vulnerability occurs because a default user account is created at installation and the account password cannot be changed. An attacker could exploit this vulnerability by logging in using XMPP to access the Openfire server using the default account. The attacker could log in using the default account an
Cisco
Cisco Finesse Desktop and Cisco Unified Contact Center Express Applications XMPP Unauthorized Access Vulnerability
vendor_cisco
CVE-2016-1307 Cisco Finesse Desktop and Cisco Unified Contact Center Express Applications XMPP Unauthorized Access Vulnerability
CVE-2016-1307: Cisco Finesse Desktop and Cisco Unified Contact Center Express Applications XMPP Unauthorized Access Vulnerability
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) in the Cisco Finesse Desktop and Cisco Unified Contact Center Express applications could allow an unauthenticated, remote attacker to log in to the device with a default account with a static password. This account provides nonadministrative access to the Openfire server bundled with the application. The vulnerability occurs because a default user account is created at installation and the account password cannot be changed. An attacker could exploit this vulnerability by logging in using XMPP to access the Openfire server using the default account. The attacker could log in using the defau
GHSA
GHSA-fvf3-v835-pwvx: The Openfire server in Cisco Finesse Desktop 10
ghsa_unreviewed·2022-05-17
CVE-2016-1307 [MEDIUM] CWE-287 GHSA-fvf3-v835-pwvx: The Openfire server in Cisco Finesse Desktop 10
The Openfire server in Cisco Finesse Desktop 10.5(1) and 11.0(1) and Unified Contact Center Express 10.6(1) has a hardcoded account, which makes it easier for remote attackers to obtain access via an XMPP session, aka Bug ID CSCuw79085.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160202-fduccehttp://www.securitytracker.com/id/1034920http://www.securitytracker.com/id/1034921http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160202-fduccehttp://www.securitytracker.com/id/1034920http://www.securitytracker.com/id/1034921
2016-02-07
Published