Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-1246— Cisco Finesse OpenSocial Gadget Editor Unauthenticated Access Vulnerability

CVSS 6.5 · Medium EPSS 0.52% · P67
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-1246

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco Finesse OpenSocial Gadget Editor Unauthenticated Access Vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
Cisco Finesse, Cisco Virtualized Voice Browser, and Cisco Unified CVP OpenSocial Gadget Editor Unauthenticated Access Vulnerability A vulnerability in the web management interface of Cisco Finesse, Cisco Virtualized Voice Browser, and Cisco Unified CVP could allow an unauthenticated, remote attacker to access the OpenSocial Gadget Editor without providing valid user credentials. The vulnerability is due to missing authentication for a specific section of the web-based management interface. An attacker could exploit this vulnerability by accessing a crafted URL. A successful exploit could allow the attacker to obtain access to a section of the interface, which they could use to obtain potentially confidential information and create arbitrary XML files. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
关键功能的认证机制缺失
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco Finesse 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco Finesse是美国思科(Cisco)公司的一套呼叫中心管理软件。 Cisco Finesse 存在跨站脚本漏洞,该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
CiscoCisco Unified Customer Voice Portal (CVP) 12.6(2)_ES4 -

II. Public POCs for CVE-2021-1246

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-1246

登录查看更多情报信息。

Same Patch Batch · Cisco · 2021-01-13 · 96 CVEs total

CVE-2021-11448.8 HIGHCisco Connected Mobile Experiences Privilege Escalation Vulnerability
CVE-2021-12377.8 HIGHCisco AnyConnect Secure Mobility Client for Windows DLL Injection Vulnerability
CVE-2021-11887.2 HIGHCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote
CVE-2021-11867.2 HIGHCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote
CVE-2021-11877.2 HIGHCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote
CVE-2021-13607.2 HIGHCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote
CVE-2021-11937.2 HIGHCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote
CVE-2021-11947.2 HIGHCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote
CVE-2021-11957.2 HIGHCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote
CVE-2021-11967.2 HIGHCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote
CVE-2021-11927.2 HIGHCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote
CVE-2021-11857.2 HIGHCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote
CVE-2021-11847.2 HIGHCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote
CVE-2021-11837.2 HIGHCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote
CVE-2021-11827.2 HIGHCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote
CVE-2021-11817.2 HIGHCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote
CVE-2021-11807.2 HIGHCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote
CVE-2021-11797.2 HIGHCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote
CVE-2021-11787.2 HIGHCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote
CVE-2021-11777.2 HIGHCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote

Showing top 20 of 96 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2021-1246

No comments yet


Leave a comment