SB2017090709 - Session hijacking in Cisco Prime LAN Management Solution



SB2017090709 - Session hijacking in Cisco Prime LAN Management Solution

Published: September 7, 2017

Security Bulletin ID SB2017090709
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Session hijacking (CVE-ID: CVE-2017-12225)

The vulnerability allows a remote authenticated attacker to perform session fixation attack on the target system.

The weakness exists in the web functionality of the Cisco Prime LAN Management Solution due to the reuse of a preauthentication session token as part of the postauthentication session. A remote attacker can obtain the presession token ID and hijack an existing user's session.

Remediation

Install update from vendor's website.