PT-2019-2555 · Cisco · Cisco Enterprise Chat/Email
Published
2019-06-19
·
Updated
2020-10-16
·
CVE-2019-1877
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Enterprise Chat and Email versions prior to 12.0(1)ES1
Description
The issue is related to insufficient protection of internal data in the HTTP API component of Cisco Enterprise Chat and Email. This could allow a remote attacker to disclose protected information by sending a specially crafted request. The vulnerability is also due to insufficient authentication mechanisms on the file download function of the API, which could allow an unauthenticated, remote attacker to download files attached through chat sessions.
Recommendations
For versions prior to 12.0(1)ES1, update to version 12.0(1)ES1 or later to resolve the issue. As a temporary workaround, consider restricting access to the file download function of the API to minimize the risk of exploitation. Avoid using the API to download files attached through chat sessions until the issue is resolved.
Fix
Improper Authentication
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Enterprise Chat/Email