SB2016101209 - Cross-site request forgery in Cisco Finesse



SB2016101209 - Cross-site request forgery in Cisco Finesse

Published: October 12, 2016 Updated: April 5, 2018

Security Bulletin ID SB2016101209
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Cross-site request forgery (CVE-ID: CVE-2016-6442)

The vulnerability allows a remote unauthenticated user to perform cross-site request forgery attack on the target system.
The weakness is due to insufficient CSRF protections. By persuading the victim to follow a malicious link or visit an attacker-controlled website, a remote user can send arbitrry requests to the target device via the web browser with the privileges of the valid user.
Successful exploitation of the vulnerability will result in performing of CSRF attack on the vulnerable system.

Remediation

Install update from vendor's website.