Cross-Site Scripting Vulnerability in Cisco Integrated Management Controller
CVE-2017-6618
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 20 April 2017
What is CVE-2017-6618?
A cross-site scripting vulnerability exists in the web-based GUI of the Cisco Integrated Management Controller (IMC) 3.0(1c), allowing an authenticated remote attacker to execute arbitrary code in the context of the affected system. This vulnerability stems from inadequate validation of user-supplied input. By tricking an authenticated user into clicking a specially crafted link, an attacker could exploit this weakness to perform malicious actions within the web-based interface.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Integrated Management Controller Cisco Integrated Management Controller
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved