Home/Product/cisco finesse
Product

cisco finesse

25 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-20278
all versions
A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execu
6.0MEDIUM
CVE-2024-20405
< 11.6\(1\)
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct
4.8MEDIUM
CVE-2024-20404
< 11.6\(1\)
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct
7.2HIGH
CVE-2023-20088
< 12.6\(1\)
A vulnerability in the nginx configurations that are provided as part of the VPN-less reverse proxy for Cisco Finesse could allow
5.3MEDIUM
CVE-2021-44228
< 12.6\(1\)
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration
10.0CRITICAL
CVE-2021-1358
<= 12.6\(1\)
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to redirect
4.7MEDIUM
CVE-2021-1254
< 12.6\(1\)
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an authenticated, remote attacker to c
4.8MEDIUM
CVE-2021-1246
< 12.0\(1\)
Cisco Finesse, Cisco Virtualized Voice Browser, and Cisco Unified CVP OpenSocial Gadget Editor Unauthenticated Access Vulnerabilit
6.5MEDIUM
CVE-2021-1245
< 12.0\(1\)
Cisco Finesse and Cisco Unified CVP OpenSocial Gadget Editor Cross-Site Scripting Vulnerability A vulnerability in the web-base
6.5MEDIUM
CVE-2020-3159
< 12.5\(1\)
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct
6.1MEDIUM
CVE-2019-15278
all versions
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to bypass a
6.1MEDIUM
CVE-2019-12632
all versions
A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-si
7.5HIGH
CVE-2018-0399
all versions
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to
9.8CRITICAL
CVE-2018-0398
all versions
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to
9.8CRITICAL
CVE-2017-6779
>= 11.5 and < 11.5\(3\)
Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaborati
7.5HIGH
CVE-2017-12337
all versions
A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platfo
9.8CRITICAL
CVE-2017-12288
all versions
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express could allow an unauthenticated, remo
6.1MEDIUM
CVE-2017-6761
all versions
A vulnerability in the web-based management interface of Cisco Finesse 10.6(1) and 11.5(1) could allow an unauthenticated, remote
6.1MEDIUM
CVE-2016-6442
all versions
A vulnerability in Cisco Finesse Agent and Supervisor Desktop Software could allow an unauthenticated, remote attacker to conduct
8.8HIGH
CVE-2016-1373
all versions
The gadgets-integration API in Cisco Finesse 8.5(1) through 8.5(5), 8.6(1), 9.0(1), 9.0(2), 9.1(1), 9.1(1)SU1, 9.1(1)SU1.1, 9.1(1)
8.6HIGH
CVE-2015-4310
all versions
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Finesse 10.5(1) allow remote attackers to inject arbitrary web script
CVE-2015-0754
all versions
Cisco Finesse 10.5(1) allows remote authenticated users to obtain sensitive information or cause a denial of service (CPU and memo
CVE-2015-0714
all versions
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Finesse Server 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote at
CVE-2013-3457
all versions
Absolute path traversal vulnerability in the web interface in Cisco Finesse allows remote attackers to read directory contents via
CVE-2013-3455
all versions
Cisco Finesse allows remote attackers to obtain sensitive information by sniffing the network for HTTP query data, aka Bug ID CSCu
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin