#VU12790 Cross-site request forgery in Network Level Service - CVE-2018-0270
Published: May 17, 2018
Network Level Service
Cisco Systems, Inc
Description
The vulnerability allows a remote unauthenticated attacker to write arbitrary files and cause DoS condition on the target system.
The weakness exists in the web-based management interface due to insufficient CSRF protections. A remote attacker can trick the victim into following a specially crafted link, perform arbitrary actions with the privilege level of the target user, write arbitrary files and cause he service to crash.