Логотип exploitDog
bind:CVE-2020-3267
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-3267

Количество 3

Количество 3

nvd логотип

CVE-2020-3267

больше 5 лет назад

A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to change the availability state of any agent. The vulnerability is due to insufficient authorization enforcement on an affected system. An attacker could exploit this vulnerability by authenticating to an affected system with valid agent credentials and performing a specific API call with crafted input. A successful exploit could allow the attacker to change the availability state of an agent, potentially causing a denial of service condition.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-9vch-84p9-292x

больше 3 лет назад

A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to change the availability state of any agent. The vulnerability is due to insufficient authorization enforcement on an affected system. An attacker could exploit this vulnerability by authenticating to an affected system with valid agent credentials and performing a specific API call with crafted input. A successful exploit could allow the attacker to change the availability state of an agent, potentially causing a denial of service condition.

CVSS3: 7.1
EPSS: Низкий
fstec логотип

BDU:2020-02749

больше 5 лет назад

Уязвимость программного средства автоматизации работы операторов Cisco Unified Contact Center Express, связанная с ошибками авторизации, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-3267

A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to change the availability state of any agent. The vulnerability is due to insufficient authorization enforcement on an affected system. An attacker could exploit this vulnerability by authenticating to an affected system with valid agent credentials and performing a specific API call with crafted input. A successful exploit could allow the attacker to change the availability state of an agent, potentially causing a denial of service condition.

CVSS3: 7.1
0%
Низкий
больше 5 лет назад
github логотип
GHSA-9vch-84p9-292x

A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to change the availability state of any agent. The vulnerability is due to insufficient authorization enforcement on an affected system. An attacker could exploit this vulnerability by authenticating to an affected system with valid agent credentials and performing a specific API call with crafted input. A successful exploit could allow the attacker to change the availability state of an agent, potentially causing a denial of service condition.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2020-02749

Уязвимость программного средства автоматизации работы операторов Cisco Unified Contact Center Express, связанная с ошибками авторизации, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.4
0%
Низкий
больше 5 лет назад

Уязвимостей на страницу