CVE-2021-1246

MEDIUM

Cisco Finesse - Unauthenticated Access to OpenSocial Gadget Editor via Crafted URL

Title source: llm
STIX 2.1

Description

Cisco Finesse, Cisco Virtualized Voice Browser, and Cisco Unified CVP OpenSocial Gadget Editor Unauthenticated Access Vulnerability A vulnerability in the web management interface of Cisco Finesse, Cisco Virtualized Voice Browser, and Cisco Unified CVP could allow an unauthenticated, remote attacker to access the OpenSocial Gadget Editor without providing valid user credentials. The vulnerability is due to missing authentication for a specific section of the web-based management interface. An attacker could exploit this vulnerability by accessing a crafted URL. A successful exploit could allow the attacker to obtain access to a section of the interface, which they could use to obtain potentially confidential information and create arbitrary XML files. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Scores

CVSS v3 6.5
EPSS 0.0052
EPSS Percentile 66.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-306 CWE-79
Status published
Products (3)
cisco/finesse 12.0\(1\) (6 CPE variants)
cisco/finesse 12.5\(1\) (5 CPE variants)
cisco/finesse < 12.0\(1\)
Published Jan 13, 2021
Tracked Since Feb 18, 2026