Remote access vulnerability in Cisco Remote Expert Manager Software
CVE-2017-6647

5.3MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
22 May 2017

Summary

A vulnerability in Cisco Remote Expert Manager Software 11.0.0 allows unauthenticated remote attackers to gain access to sensitive Temporary File information. This flaw is a result of insufficient protection for sensitive data when responding to HTTP requests through the web interface. Attackers can exploit this vulnerability by sending crafted HTTP requests, potentially uncovering critical information that could facilitate further attacks. It underscores the importance of implementing robust security measures to safeguard sensitive data within software environments.

Affected Version(s)

Cisco Remote Expert Manager Cisco Remote Expert Manager

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.