CVE-2018-15508

Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control allowing a remote attackers to cause a denial of service via opening a connection on port 8083 to a device running the Five9 SoftPhone(issue 1 of 2).
References
Link Resource
https://0tkombo.wixsite.com/0tkombo/blog/five9-dos-websocket-access Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:five9:agent_desktop_plus:10.0.70:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-03-21 16:00

Updated : 2024-02-28 17:08


NVD link : CVE-2018-15508

Mitre link : CVE-2018-15508

CVE.ORG link : CVE-2018-15508


JSON object : View

Products Affected

five9

  • agent_desktop_plus
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource