Remote Data Access Vulnerability in Cisco Prime Infrastructure and Evolved Programmable Network Manager
CVE-2017-3884
6.5MEDIUM
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 7 April 2017
Summary
A security vulnerability in the web interface of Cisco Prime Infrastructure and Evolved Programmable Network (EPN) Manager allows authenticated, remote attackers to access sensitive information. This access does not require admin credentials, which could be exploited for further reconnaissance attacks. Affected versions include multiple iterations of Cisco Prime Infrastructure, putting numerous deployments at risk. Remediation is critical to protect against unauthorized access and ensure system integrity.
Affected Version(s)
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved