Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-1660

Опубликовано: 07 фев. 2019
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

A vulnerability in the Simple Object Access Protocol (SOAP) of Cisco TelePresence Management Suite (TMS) software could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to a lack of proper access and authentication controls on the affected TMS software. An attacker could exploit this vulnerability by gaining access to internal, trusted networks to send crafted SOAP calls to the affected device. If successful, an exploit could allow the attacker to access system management tools. Under normal circumstances, this access should be prohibited.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:telepresence_management_suite:15.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:telepresence_management_suite:15.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:telepresence_management_suite:15.2.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:telepresence_management_suite:15.3:*:*:*:*:*:*:*
cpe:2.3:a:cisco:telepresence_management_suite:15.4:*:*:*:*:*:*:*
cpe:2.3:a:cisco:telepresence_management_suite:15.5:*:*:*:*:*:*:*
cpe:2.3:a:cisco:telepresence_management_suite:15.6:*:*:*:*:*:*:*
cpe:2.3:a:cisco:telepresence_management_suite:15.7:*:*:*:*:*:*:*

EPSS

Процентиль: 81%
0.01589
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-284
CWE-264

Связанные уязвимости

CVSS3: 5.3
github
больше 3 лет назад

A vulnerability in the Simple Object Access Protocol (SOAP) of Cisco TelePresence Management Suite (TMS) software could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to a lack of proper access and authentication controls on the affected TMS software. An attacker could exploit this vulnerability by gaining access to internal, trusted networks to send crafted SOAP calls to the affected device. If successful, an exploit could allow the attacker to access system management tools. Under normal circumstances, this access should be prohibited.

CVSS3: 5.3
fstec
около 7 лет назад

Уязвимость компонента Simple Object Access Protocol программного средства централизованного управления видеосистемами предприятия Cisco TelePresence Management Suite, позволяющая нарушителю получить доступ к инструментам управления

EPSS

Процентиль: 81%
0.01589
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-284
CWE-264