PT-2019-2555 · Cisco · Cisco Enterprise Chat/Email

Publicado

2019-06-19

·

Atualizado

2020-10-16

·

CVE-2019-1877

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Enterprise Chat and Email versions prior to 12.0(1)ES1
Description The issue is related to insufficient protection of internal data in the HTTP API component of Cisco Enterprise Chat and Email. This could allow a remote attacker to disclose protected information by sending a specially crafted request. The vulnerability is also due to insufficient authentication mechanisms on the file download function of the API, which could allow an unauthenticated, remote attacker to download files attached through chat sessions.
Recommendations For versions prior to 12.0(1)ES1, update to version 12.0(1)ES1 or later to resolve the issue. As a temporary workaround, consider restricting access to the file download function of the API to minimize the risk of exploitation. Avoid using the API to download files attached through chat sessions until the issue is resolved.

Correção

Improper Authentication

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02407
CVE-2019-1877

Produtos afetados

Cisco Enterprise Chat/Email