Remote Code Execution and XSS Vulnerabilities in Cisco Data Center Network Manager
CVE-2017-12344

6.1MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
30 November 2017

Summary

Cisco Data Center Network Manager (DCNM) Software has multiple vulnerabilities that could be exploited by remote attackers. These vulnerabilities allow malicious individuals to inject arbitrary values into configuration parameters, redirect users to malicious websites, and compromise the DCNM client interface via code injection and cross-site scripting techniques. Successful exploitation may result in unauthorized access and manipulation of sensitive data, compromising the security and integrity of the affected devices and networks.

Affected Version(s)

Cisco Data Center Network Manager Software Cisco Data Center Network Manager Software

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.