← Back

CVE-2016-1373

nvd nist
Published: May 5, 2016Modified: May 6, 2026

JSON object

Loading...
8.6
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 4.0
Source: NVD

Description

The gadgets-integration API in Cisco Finesse 8.5(1) through 8.5(5), 8.6(1), 9.0(1), 9.0(2), 9.1(1), 9.1(1)SU1, 9.1(1)SU1.1, 9.1(1)ES1 through 9.1(1)ES5, 10.0(1), 10.0(1)SU1, 10.0(1)SU1.1, 10.5(1), 10.5(1)ES1 through 10.5(1)ES4, 10.5(1)SU1, 10.5(1)SU1.1, 10.5(1)SU1.7, 10.6(1), 10.6(1)SU1, 10.6(1)SU2, and 11.0(1) allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted request, aka Bug ID CSCuw86623.

Affected (31)

Products: Cisco: Finesse
1 product
Finesse
Configuration A
31 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 10.0(1)_base
Version 10.0(1)_su1.1
Version 10.0(1)_su1
Version 10.5(1)_base
Version 10.5(1)_es1
Version 10.5(1)_es2
Version 10.5(1)_es3
Version 10.5(1)_es4
Version 10.5(1)_su1.1
Version 10.5(1)_su1.7
Version 10.5(1)_su1
Version 10.6(1)_base
Version 10.6(1)_su1
Version 10.6(1)_su2
Version 11.0(1)_base
Version 8.5(1)_base
Version 8.5(2)_base
Version 8.5(3)_base
Version 8.5(4)_base
Version 8.5(5)_base
Version 8.6(1)_base
Version 9.0(1)_base
Version 9.0(2)_base
Version 9.1(1)_base
Version 9.1(1)_es1
Version 9.1(1)_es2
Version 9.1(1)_es3
Version 9.1(1)_es4
Version 9.1(1)_es5
Version 9.1(1)_su1.1
Version 9.1(1)_su1

Timeline

No history available yet.