Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-15448

Опубликовано: 08 нояб. 2018
Источник: nvd
CVSS3: 5.3
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

A vulnerability in the user management functions of Cisco Registered Envelope Service could allow an unauthenticated, remote attacker to discover sensitive user information. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to an insecure configuration that allows improper indexing. An attacker could exploit this vulnerability by using a search engine to look for specific data strings. A successful exploit could allow the attacker to discover certain sensitive information about the application, including usernames.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:registered_envelope_service:-:*:*:*:*:*:*:*

EPSS

Процентиль: 79%
0.01216
Низкий

5.3 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-16
NVD-CWE-Other

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

A vulnerability in the user management functions of Cisco Registered Envelope Service could allow an unauthenticated, remote attacker to discover sensitive user information. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to an insecure configuration that allows improper indexing. An attacker could exploit this vulnerability by using a search engine to look for specific data strings. A successful exploit could allow the attacker to discover certain sensitive information about the application, including usernames.

CVSS3: 4.3
fstec
больше 7 лет назад

Уязвимость функций управления пользователями средства защиты передаваемой информации Cisco Registered Envelope Service, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 79%
0.01216
Низкий

5.3 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-16
NVD-CWE-Other