PT-2016-4699 · Ignite Realtime+1 · Openfire Server+2

Publicado

2016-02-07

·

Atualizado

2016-12-06

·

CVE-2016-1307

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco Finesse Desktop versions 10.5(1) through 11.0(1) Unified Contact Center Express version 10.6(1)
Description The issue concerns a hardcoded account in the Openfire server, which can be exploited by remote attackers to gain access via an XMPP session.
Recommendations For Cisco Finesse Desktop versions 10.5(1) through 11.0(1), consider disabling the Openfire server until a patch is available. For Unified Contact Center Express version 10.6(1), restrict access to the Openfire server to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-1307

Produtos afetados

Cisco Finesse Desktop
Openfire Server
Cisco Unified Contact Center Express