Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-20175

Опубликовано: 03 июн. 2026
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks.

This vulnerability is due to insufficient validation of user-supplied input for HTTP requests that are sent to an affected device. An attacker who has knowledge of the address of the affected device could exploit this vulnerability by persuading a user to click a crafted link that contains the affected device address. A successful exploit could allow the attacker to conduct browser-based attacks and execute arbitrary script code in the context of the affected interface or access sensitive information on the affected device.

EPSS

Процентиль: 8%
0.0018
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-73

Связанные уязвимости

CVSS3: 6.1
github
2 месяца назад

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks. This vulnerability is due to insufficient validation of user-supplied input for HTTP requests that are sent to an affected device. An attacker who has knowledge of the address of the affected device could exploit this vulnerability by persuading a user to click a crafted link that contains the affected device address. A successful exploit could allow the attacker to conduct browser-based attacks and execute arbitrary script code in the context of the affected interface or access sensitive information on the affected device.

CVSS3: 6.1
fstec
2 месяца назад

Уязвимость программного средства автоматизации работы операторов Cisco Finesse, связанная с некорректным внешним управлением именем или путем файла, позволяющая нарушителю выполнить произвольный код или получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 8%
0.0018
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-73