CVE-2018-15448 MEDIUM

CVE-2018-15448: Cisco Registered Envelope Service Information Disclosure Vulnerability

Vendor Cisco
Product Cisco Registered Envelope Service
Weakness CWE-16
Published November 8, 2018
Last update November 26, 2024

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

A vulnerability in the user management functions of Cisco Registered Envelope Service could allow an unauthenticated, remote attacker to discover sensitive user information. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to an insecure configuration that allows improper indexing. An attacker could exploit this vulnerability by using a search engine to look for specific data strings. A successful exploit could allow the attacker to discover certain sensitive information about the application, including usernames.

Key dates

02Disclosure timeline

November 8, 2018 CVE published
November 26, 2024 Record updated