Improper Authentication in Cisco Finesse - CVE-2021-1246
Published: January 19, 2021
Cisco Finesse
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to missing authentication for a specific section of the web-based management interface. A remote attacker can obtain access to a section of the interface, which they could use to obtain potentially confidential information and create arbitrary XML files.