Remote Code Injection and XSS Vulnerabilities in Cisco Data Center Network Manager
CVE-2017-12347
6.1MEDIUM
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 30 November 2017
Summary
Cisco Data Center Network Manager (DCNM) Software is affected by multiple vulnerabilities that could permit an attacker to inject arbitrary values into configuration parameters, potentially leading to unauthorized configuration changes, user redirection to malicious sites, and the ability to perform cross-site scripting (XSS) attacks on users utilizing the software. These vulnerabilities expose organizations to significant security risks, as they can be exploited without requiring physical access to the network.
Affected Version(s)
Cisco Data Center Network Manager Software Cisco Data Center Network Manager Software
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved