CVE-2020-3402

HIGH

Cisco Unified Customer Voice Portal - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability in the Java Remote Method Invocation (RMI) interface of Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability exists because certain RMI listeners are not properly authenticated. An attacker could exploit this vulnerability by sending a crafted request to the affected listener. A successful exploit could allow the attacker to access sensitive information on an affected device.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0051
EPSS Percentile 66.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
cisco/unified_customer_voice_portal < 12.5\(1\)
Published Jul 02, 2020
Tracked Since Feb 18, 2026