Skip to main content

Vendor/product archive

cisco / finesse CVEs

Beta · best-effort

24 CVEs tagged to cisco / finesse3 Critical, 6 High, 15 Medium, 0 Low, 0 Unrated.

CVE-2025-20278

Published Jun 4, 2025

A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-20405

Published Jun 5, 2024

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an RFI vulnerab…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20404

Published Jun 5, 2024

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected system. This vul…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-20088

Published Mar 3, 2023

A vulnerability in the nginx configurations that are provided as part of the VPN-less reverse proxy for Cisco Finesse could allow an unauthenticated, remote attacker to create a d…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1358

Published May 22, 2021

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. This vulnerabil…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1254

Published May 22, 2021

Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack agains…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1246

Published Jan 13, 2021

Cisco Finesse, Cisco Virtualized Voice Browser, and Cisco Unified CVP OpenSocial Gadget Editor Unauthenticated Access Vulnerability A vulnerability in the web management interf…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1245

Published Jan 13, 2021

Cisco Finesse and Cisco Unified CVP OpenSocial Gadget Editor Cross-Site Scripting Vulnerability A vulnerability in the web-based management interface of Cisco Finesse and Cisco…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-3159

Published Feb 19, 2020

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a use…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12632

Published Sep 5, 2019

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on an affected s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0399

Published Jul 18, 2018

Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to retrieve a cleartext password from an affected s…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-0398

Published Jul 18, 2018

Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) att…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12337

Published Nov 16, 2017

A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an unauthenticated, remote attacke…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2017-12288

Published Oct 19, 2017

A vulnerability in the web-based management interface of Cisco Unified Contact Center Express could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XS…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6761

Published Aug 7, 2017

A vulnerability in the web-based management interface of Cisco Finesse 10.6(1) and 11.5(1) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS)…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6442

Published Oct 27, 2016

A vulnerability in Cisco Finesse Agent and Supervisor Desktop Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack agains…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1373

Published May 5, 2016

The gadgets-integration API in Cisco Finesse 8.5(1) through 8.5(5), 8.6(1), 9.0(1), 9.0(2), 9.1(1), 9.1(1)SU1, 9.1(1)SU1.1, 9.1(1)ES1 through 9.1(1)ES5, 10.0(1), 10.0(1)SU1, 10.0(…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4310

Published Aug 19, 2015

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Finesse 10.5(1) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0754

Published May 29, 2015

Cisco Finesse 10.5(1) allows remote authenticated users to obtain sensitive information or cause a denial of service (CPU and memory consumption) via a crafted XML document, aka B…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0714

Published May 2, 2015

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Finesse Server 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote attackers to inject arbitrary web script or HTML vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3457

Published Aug 12, 2013

Absolute path traversal vulnerability in the web interface in Cisco Finesse allows remote attackers to read directory contents via a direct request to a directory URL, aka Bug ID…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3455

Published Aug 12, 2013

Cisco Finesse allows remote attackers to obtain sensitive information by sniffing the network for HTTP query data, aka Bug ID CSCug16732.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1