Remote Data Exposure in Cisco Remote Expert Manager Software
CVE-2017-6642

5.3MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
22 May 2017

Summary

The web interface of Cisco Remote Expert Manager Software 11.0.0 is subject to a vulnerability that allows an unauthenticated remote attacker to access sensitive information. This occurs due to insufficient protection of sensitive data in the HTTP responses from the software's web interface. Attackers can exploit this flaw by sending specially crafted HTTP requests, potentially leading to unauthorized access to critical information that may facilitate further attacks. Proper security measures should be implemented to mitigate this risk.

Affected Version(s)

Cisco Remote Expert Manager Cisco Remote Expert Manager

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.