Information Disclosure Vulnerability in Cisco Remote Expert Manager Software
CVE-2017-6644
5.3MEDIUM
Summary
The Cisco Remote Expert Manager Software version 11.0.0 is vulnerable due to inadequate protection of sensitive data during HTTP requests. An unauthenticated remote attacker can exploit this weakness by sending specifically crafted HTTP requests to the web interface. This could lead to the exposure of sensitive information, which may further facilitate reconnaissance attacks on the system. Cisco Bug ID for reference: CSCvc52860.
Affected Version(s)
Cisco Remote Expert Manager Cisco Remote Expert Manager
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved