Remote Information Disclosure in Cisco Remote Expert Manager Software
CVE-2017-6646

5.3MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
22 May 2017

Summary

A flaw in the web interface of Cisco's Remote Expert Manager Software version 11.0.0 could enable unauthenticated remote attackers to gain unauthorized access to sensitive order details. This security lapse arises from the software's inadequate protection of sensitive data in its responses to HTTP requests. By submitting specially crafted requests to the web interface, an attacker may successfully retrieve confidential information, subsequently leveraging this data for further reconnaissance and potential exploitation.

Affected Version(s)

Cisco Remote Expert Manager Cisco Remote Expert Manager

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.