Vulnslist

find the latest Cisco vulnerabilities

Cisco Finesse for Cisco Unified Contact Center Enterprise Information Disclosure Vulnerability

cisco-sa-20170503-finesse-ucce · Medium · Published · Updated

A vulnerability in the Cisco Finesse Notification Service for Cisco Unified Contact Center Enterprise (UCCE) could allow an unauthenticated, remote attacker to retrieve information from agents using the Finesse Desktop. The vulnerability is due to the existence of a user account that has an undocumented, hard-coded password. An attacker could exploit this vulnerability by using the hard-coded credentials to subscribe to the Finesse Notification Service, which would allow the attacker to receive notifications when an agent signs in or out of the Finesse Desktop, when information about an agent changes, or when an agent's state changes. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170503-finesse-ucce

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2017-6626
Cisco Bug IDsCSCvc08314
CVSS ScoreBase 5.3
Base 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Unified Contact Center Enterprise

Related Products

Product CVE Evidence
Cisco Finesse CVE-2017-6626 Cisco OpenVuln
Cisco Unified Contact Center CVE-2017-6626 Cisco OpenVuln
Cisco Unified Contact Center Enterprise CVE-2017-6626 Cisco OpenVuln