SB2019020712 - Information disclosure in Cisco TelePresence Management Suite
Published: February 7, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2019-1660)
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists in the Simple Object Access Protocol (SOAP) due to a lack of proper access and authentication controls on the affected TMS software. A remote attacker can gain access to internal, trusted networks to send crafted SOAP calls to the affected device and access system management tools.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.