PT-2016-4699 · Ignite Realtime+1 · Openfire Server+2
Published
2016-02-07
·
Updated
2016-12-06
·
CVE-2016-1307
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Finesse Desktop versions 10.5(1) through 11.0(1)
Unified Contact Center Express version 10.6(1)
Description
The issue concerns a hardcoded account in the Openfire server, which can be exploited by remote attackers to gain access via an XMPP session.
Recommendations
For Cisco Finesse Desktop versions 10.5(1) through 11.0(1), consider disabling the Openfire server until a patch is available.
For Unified Contact Center Express version 10.6(1), restrict access to the Openfire server to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Finesse Desktop
Openfire Server
Cisco Unified Contact Center Express