Remote Attack Vulnerability in Cisco Remote Expert Manager Software
CVE-2017-6643
5.3MEDIUM
Summary
A vulnerability exists in the web interface of Cisco Remote Expert Manager Software 11.0.0 that could enable an unauthenticated, remote attacker to gain unauthorized access to sensitive Virtual Directory information. This issue arises from insufficient data protection in the software’s response to HTTP requests directed at its web interface. By sending crafted HTTP requests, an attacker may exploit this weakness to gather sensitive information about the software, potentially facilitating further reconnaissance or targeted attacks. For more details on this issue, you can refer to Cisco's official advisory.
Affected Version(s)
Cisco Remote Expert Manager Cisco Remote Expert Manager
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved