PT-2016-4699 · Ignite Realtime+1 · Openfire Server+2
Publicado
2016-02-07
·
Atualizado
2016-12-06
·
CVE-2016-1307
CVSS v2.0
5.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Finesse Desktop versions 10.5(1) through 11.0(1)
Unified Contact Center Express version 10.6(1)
Description
The issue concerns a hardcoded account in the Openfire server, which can be exploited by remote attackers to gain access via an XMPP session.
Recommendations
For Cisco Finesse Desktop versions 10.5(1) through 11.0(1), consider disabling the Openfire server until a patch is available.
For Unified Contact Center Express version 10.6(1), restrict access to the Openfire server to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cisco Finesse Desktop
Openfire Server
Cisco Unified Contact Center Express