CVE-2021-1246 (CNNVD-202101-957)
中文标题:
Cisco Finesse 跨站脚本漏洞
英文标题:
Cisco Finesse OpenSocial Gadget Editor Unauthenticated Access Vulnerability
漏洞描述
中文描述:
Cisco Finesse是美国思科(Cisco)公司的一套呼叫中心管理软件。 Cisco Finesse 存在跨站脚本漏洞,该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。
英文描述:
Cisco Finesse, Cisco Virtualized Voice Browser, and Cisco Unified CVP OpenSocial Gadget Editor Unauthenticated Access Vulnerability A vulnerability in the web management interface of Cisco Finesse, Cisco Virtualized Voice Browser, and Cisco Unified CVP could allow an unauthenticated, remote attacker to access the OpenSocial Gadget Editor without providing valid user credentials. The vulnerability is due to missing authentication for a specific section of the web-based management interface. An attacker could exploit this vulnerability by accessing a crafted URL. A successful exploit could allow the attacker to obtain access to a section of the interface, which they could use to obtain potentially confidential information and create arbitrary XML files. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco Unified Customer Voice Portal (CVP) | 12.6(2)_ES4 | - | - |
cpe:2.3:a:cisco:cisco_unified_customer_voice_portal_(cvp):12.6(2)_es4:*:*:*:*:*:*:*
|
| Cisco | Cisco Unified Customer Voice Portal (CVP) | 12.6(2)_ET5 | - | - |
cpe:2.3:a:cisco:cisco_unified_customer_voice_portal_(cvp):12.6(2)_et5:*:*:*:*:*:*:*
|
| Cisco | Cisco Unified Customer Voice Portal (CVP) | 12.6(2)_ET7 | - | - |
cpe:2.3:a:cisco:cisco_unified_customer_voice_portal_(cvp):12.6(2)_et7:*:*:*:*:*:*:*
|
| Cisco | Cisco Unified Customer Voice Portal (CVP) | 12.6(2)_ET8 | - | - |
cpe:2.3:a:cisco:cisco_unified_customer_voice_portal_(cvp):12.6(2)_et8:*:*:*:*:*:*:*
|
| Cisco | Cisco Unified Customer Voice Portal (CVP) | 12.6(2)_ES9 | - | - |
cpe:2.3:a:cisco:cisco_unified_customer_voice_portal_(cvp):12.6(2)_es9:*:*:*:*:*:*:*
|
| Cisco | Cisco Unified Customer Voice Portal (CVP) | 12.6(2)_ES10 | - | - |
cpe:2.3:a:cisco:cisco_unified_customer_voice_portal_(cvp):12.6(2)_es10:*:*:*:*:*:*:*
|
| Cisco | Cisco Unified Customer Voice Portal (CVP) | 12.6(2)_ES11 | - | - |
cpe:2.3:a:cisco:cisco_unified_customer_voice_portal_(cvp):12.6(2)_es11:*:*:*:*:*:*:*
|
| Cisco | Cisco Unified Customer Voice Portal (CVP) | 12.6(2)_ET12 | - | - |
cpe:2.3:a:cisco:cisco_unified_customer_voice_portal_(cvp):12.6(2)_et12:*:*:*:*:*:*:*
|
| Cisco | Cisco Unified Customer Voice Portal (CVP) | 12.6(2)_ET13 | - | - |
cpe:2.3:a:cisco:cisco_unified_customer_voice_portal_(cvp):12.6(2)_et13:*:*:*:*:*:*:*
|
| Cisco | Cisco Unified Customer Voice Portal (CVP) | 12.6(2)_ES14 | - | - |
cpe:2.3:a:cisco:cisco_unified_customer_voice_portal_(cvp):12.6(2)_es14:*:*:*:*:*:*:*
|
| Cisco | Cisco Unified Customer Voice Portal (CVP) | 12.6(2)_ES15 | - | - |
cpe:2.3:a:cisco:cisco_unified_customer_voice_portal_(cvp):12.6(2)_es15:*:*:*:*:*:*:*
|
| Cisco | Cisco Unified Customer Voice Portal (CVP) | 12.6(2)_ET16 | - | - |
cpe:2.3:a:cisco:cisco_unified_customer_voice_portal_(cvp):12.6(2)_et16:*:*:*:*:*:*:*
|
| Cisco | Cisco Unified Customer Voice Portal (CVP) | 12.6(2)_ET17 | - | - |
cpe:2.3:a:cisco:cisco_unified_customer_voice_portal_(cvp):12.6(2)_et17:*:*:*:*:*:*:*
|
| cisco | finesse | * | - | - |
cpe:2.3:a:cisco:finesse:*:*:*:*:*:*:*:*
|
| cisco | finesse | 12.0\(1\) | - | - |
cpe:2.3:a:cisco:finesse:12.0\(1\):-:*:*:*:*:*:*
|
| cisco | finesse | 12.5\(1\) | - | - |
cpe:2.3:a:cisco:finesse:12.5\(1\):-:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.1 (cna)
MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/RL:X/RC:X/E:X
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2021-1246 |
2025-11-11 15:20:45 | 2025-11-11 07:36:33 |
| NVD | nvd_CVE-2021-1246 |
2025-11-11 14:57:33 | 2025-11-11 07:44:55 |
| CNNVD | cnnvd_CNNVD-202101-957 |
2025-11-11 15:10:34 | 2025-11-11 07:56:36 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 跨站脚本
- cnnvd_id: 未提取 -> CNNVD-202101-957
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 13 -> 16
- references_count: 1 -> 2
- data_sources: ['cve'] -> ['cve', 'nvd']