Cross-Site Request Forgery Vulnerability in Cisco Finesse Software
CVE-2016-6442
8.8HIGH
Summary
A vulnerability exists in Cisco Finesse Agent and Supervisor Desktop Software that enables an unauthenticated, remote attacker to launch a cross-site request forgery (CSRF) attack. This flaw may allow the attacker to manipulate requests made by the user while interacting with the web interface, leading to potential unauthorized actions within the affected software. Security measures and configurations should be reviewed to mitigate the risks associated with this vulnerability.
Affected Version(s)
Cisco Finesse 11.0(1) Cisco Finesse 11.0(1)
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved