Remote Code Execution and XSS Vulnerabilities in Cisco Data Center Network Manager
CVE-2017-12344
6.1MEDIUM
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 30 November 2017
Summary
Cisco Data Center Network Manager (DCNM) Software has multiple vulnerabilities that could be exploited by remote attackers. These vulnerabilities allow malicious individuals to inject arbitrary values into configuration parameters, redirect users to malicious websites, and compromise the DCNM client interface via code injection and cross-site scripting techniques. Successful exploitation may result in unauthorized access and manipulation of sensitive data, compromising the security and integrity of the affected devices and networks.
Affected Version(s)
Cisco Data Center Network Manager Software Cisco Data Center Network Manager Software
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved