Vulnerability identifier: #VU6984
Vulnerability risk: Medium
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID:
CWE-ID:
CWE-352
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Cisco Prime Collaboration Assurance
Server applications /
Other server solutions
Vendor: Cisco Systems, Inc
Description
The vulnerability allows a remote unauthenticated attacker to perform CSRF attack.
The weakness exists in the web-based management interface of Cisco Prime Collaboration Assurance due to insufficient CSRF protections for the web-based management interface. A remote attacker can trick the victim into following a specially crafted link, get access to the affected system and perform arbitrary actions.
Successful exploitation of the vulnerability results in access to the system.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Cisco Prime Collaboration Assurance: 11.5 - 11.6
External links
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-pca
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.