Remote Information Disclosure in Cisco Remote Expert Manager Software
CVE-2017-6646
What is CVE-2017-6646?
A flaw in the web interface of Cisco's Remote Expert Manager Software version 11.0.0 could enable unauthenticated remote attackers to gain unauthorized access to sensitive order details. This security lapse arises from the software's inadequate protection of sensitive data in its responses to HTTP requests. By submitting specially crafted requests to the web interface, an attacker may successfully retrieve confidential information, subsequently leveraging this data for further reconnaissance and potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Remote Expert Manager Cisco Remote Expert Manager
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved