CVE-2020-3402
Cisco Unified Customer Voice Portal Information Disclosure Vulnerability
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.3EPSS 1.6%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
02 jul 2020Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability in the Java Remote Method Invocation (RMI) interface of Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability exists because certain RMI listeners are not properly authenticated. An attacker could exploit this vulnerability by sending a crafted request to the affected listener. A successful exploit could allow the attacker to access sensitive information on an affected device.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Productos afectados
Cisco · Cisco Unified IP Interactive Voice Response (IVR)¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →