Session Fixation Vulnerability in Cisco Prime LAN Management Solution
CVE-2017-12225
6.5MEDIUM
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 7 September 2017
What is CVE-2017-12225?
A flaw in the web functionality of the Cisco Prime LAN Management Solution allows an authenticated attacker to hijack another user's administrative session. This Session Fixation Vulnerability stems from the reuse of a preauthentication session token in the postauthentication session. By exploiting this weakness, an attacker can obtain the presession token ID to take control of an existing user's session. It is essential for administrators using affected versions to implement proper security measures to mitigate this risk.
Affected Version(s)
Cisco Prime LAN Management Solution Cisco Prime LAN Management Solution