SB2018051720 - Cross-site request forgery in Cisco Network Level Service
Published: May 17, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cross-site request forgery (CVE-ID: CVE-2018-0270)
The vulnerability allows a remote unauthenticated attacker to write arbitrary files and cause DoS condition on the target system.
The weakness exists in the web-based management interface due to insufficient CSRF protections. A remote attacker can trick the victim into following a specially crafted link, perform arbitrary actions with the privilege level of the target user, write arbitrary files and cause he service to crash.
Remediation
Install update from vendor's website.