Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control allowing a remote attackers to cause a denial of service via opening a connection on port 8083 to a device running the Five9 SoftPhone(issue 1 of 2).
References
Link | Resource |
---|---|
https://0tkombo.wixsite.com/0tkombo/blog/five9-dos-websocket-access | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2019-03-21 16:00
Updated : 2024-02-28 17:08
NVD link : CVE-2018-15508
Mitre link : CVE-2018-15508
CVE.ORG link : CVE-2018-15508
JSON object : View
Products Affected
five9
- agent_desktop_plus
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource