Vulnslist

find the latest Cisco vulnerabilities

Cisco Finesse XML Processing Denial of Service Vulnerability

Cisco-SA-20150527-CVE-2015-0754 · Medium · Published · Updated

A vulnerability in Cisco Finesse could allow an authenticated, remote attacker to gain access to sensitive information or cause a denial of service (DoS) condition. The vulnerability is due to improper processing of XML files by an affected device. An authenticated, remote attacker could exploit this vulnerability by sending a malicious XML file to the affected device. Processing the malicious XML file could cause the device to consume excessive amounts of CPU and memory resources that could trigger a DoS condition. The attacker could also gain access to sensitive information on the device, which could be leveraged to conduct further attacks. Cisco has confirmed the vulnerability; however, software updates are not available. To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement may reduce the likelihood of a successful exploit.

Workarounds

Administrators are advised to contact the vendor regarding future updates and releases.

Administrators are advised to allow only trusted users to have network access.

Administrators may consider using IP-based access control lists (ACLs) to allow only trusted systems to access the affected systems.

Administrators are advised to monitor affected systems.

CVEsCVE-2015-0754
Cisco Bug IDsCSCut95810
CVSS ScoreBase 5.5
Base 5.5 AV:N/AC:L/Au:S/C:P/I:N/A:P/E:POC/RL:U/RC:C
Product Names From Source
Cisco Finesse

Related Products

Product CVE Evidence
Cisco Finesse CVE-2015-0754 Cisco OpenVuln