7.5
CVSSv3

CVE-2019-12632

Published: 05/09/2019 Updated: 08/10/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

A vulnerability in Cisco Finesse could allow an unauthenticated, remote malicious user to bypass access controls and conduct a server-side request forgery (SSRF) attack on an affected system. The vulnerability exists because the affected system does not properly validate user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to a user of the web application. A successful exploit could allow the malicious user to access the system and perform unauthorized actions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco finesse 11.6\\(1\\)

cisco finesse 12.5\\(1\\)

cisco finesse 12.0\\(1\\)

Vendor Advisories

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on an affected system The vulnerability exists because the affected system does not properly validate user-supplied input An attacker could exploit this vulnerability by sending a craft ...