CVE-2019-1877 is a medium-severity vulnerability affecting Cisco Enterprise Chat and Email versions prior to 12.0(1)ES1. It allows an unauthenticated, remote attacker to download files attached in chat sessions due to insufficient authentication in the HTTP API's file download function. Exploitation requires sending a crafted request, potentially leading to unauthorized disclosure of sensitive information. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.6\(1\)es9CPE matchmatch criteria | cpe:2.3:a:cisco:enterprise_chat_and_email:11.6\(1\)es9:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.