Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-20139

Опубликовано: 02 апр. 2025
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.

This vulnerability is due to improper validation of user-supplied input to chat entry points. An attacker could exploit this vulnerability by sending malicious requests to a messaging chat entry point in the affected application. A successful exploit could allow the attacker to cause the application to stop responding, resulting in a DoS condition. The application may not recover on its own and may need an administrator to manually restart services to recover.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:enterprise_chat_and_email:*:*:*:*:*:*:*:*
Версия до 12.6\(1\)es10 (исключая)

EPSS

Процентиль: 52%
0.00295
Низкий

7.5 High

CVSS3

Дефекты

CWE-185

Связанные уязвимости

CVSS3: 7.5
github
10 месяцев назад

A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper validation of user-supplied input to chat entry points. An attacker could exploit this vulnerability by sending malicious requests to a messaging chat entry point in the affected application. A successful exploit could allow the attacker to cause the application to stop responding, resulting in a DoS condition. The application may not recover on its own and may need an administrator to manually restart services to recover.

CVSS3: 7.5
fstec
10 месяцев назад

Уязвимость функции обмена сообщениями в чате средства обмена сообщениями Cisco Enterprise Chat and Email (ECE), позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 52%
0.00295
Низкий

7.5 High

CVSS3

Дефекты

CWE-185