CVE-2018-0398
published 2018-07-18CVE-2018-0398: Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-side…
PriorityP358critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.06%
79.1th percentile
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack. Cisco Bug IDs: CSCvg71018.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | finesse | — | — |
| cisco | finesse | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ghx8-6gxc-7q56: Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-si
ghsa_unreviewed·2022-05-13
CVE-2018-0398 [CRITICAL] CWE-918 GHSA-ghx8-6gxc-7q56: Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-si
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack. Cisco Bug IDs: CSCvg71018.
Cisco
Multiple Vulnerabilities in Cisco Finesse
vendor_cisco·2018-07-18·CVSS 5.8
CVE-2018-0398 [MEDIUM] CWE-19 Multiple Vulnerabilities in Cisco Finesse
Multiple Vulnerabilities in Cisco Finesse
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack or retrieve a cleartext password from an affected system.
For more information about these vulnerabilities, see the Details section of this security advisory.
There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180718-finesse
Cisco
Multiple Vulnerabilities in Cisco Finesse
vendor_cisco·CVSS 3.0
CVE-2018-0398 Multiple Vulnerabilities in Cisco Finesse
CVE-2018-0398: Multiple Vulnerabilities in Cisco Finesse
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack or retrieve a cleartext password from an affected system. For more information about these vulnerabilities, see the
CVSS: 3.0
CWE: CWE-19, CWE-264, CWE-19, CWE-264
Bug IDs: CSCvg71018, CSCvg71044, CSCvg71018, CSCvg71044
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-07-18
Published