#VU6984 Cross-site request forgery in Cisco Prime Collaboration Assurance - CVE-2017-6659 

 

#VU6984 Cross-site request forgery in Cisco Prime Collaboration Assurance - CVE-2017-6659

Published: June 8, 2017 / Updated: June 9, 2017


Vulnerability identifier: #VU6984
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2017-6659
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Cisco Prime Collaboration Assurance
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote unauthenticated attacker to perform CSRF attack.

The weakness exists in the web-based management interface of Cisco Prime Collaboration Assurance due to insufficient CSRF protections for the web-based management interface. A remote attacker can trick the victim into following a specially crafted link, get access to the affected system and perform arbitrary actions.

Successful exploitation of the vulnerability results in access to the system.

Remediation

Install update from vendor's website.

External links