Cross-site request forgery in Cisco Prime Collaboration Assurance - CVE-2017-6659
Published: June 8, 2017 / Updated: June 9, 2017
Vulnerability identifier: #VU6984
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6659
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to perform CSRF attack.
The weakness exists in the web-based management interface of Cisco Prime Collaboration Assurance due to insufficient CSRF protections for the web-based management interface. A remote attacker can trick the victim into following a specially crafted link, get access to the affected system and perform arbitrary actions.
Successful exploitation of the vulnerability results in access to the system.
The weakness exists in the web-based management interface of Cisco Prime Collaboration Assurance due to insufficient CSRF protections for the web-based management interface. A remote attacker can trick the victim into following a specially crafted link, get access to the affected system and perform arbitrary actions.
Successful exploitation of the vulnerability results in access to the system.
Affected software
Cisco Prime Collaboration Assurance
How to mitigate CVE-2017-6659
Install update from vendor's website.