Cisco Industrial Ethernet 1000 Series Switches Device Manager Vulnerability
CVE-2017-6634
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 22 May 2017
What is CVE-2017-6634?
A vulnerability exists in the Device Manager web interface of Cisco Industrial Ethernet 1000 Series Switches 1.3, which allows an unauthenticated remote attacker to execute cross-site request forgery (CSRF) attacks. The flaw is due to inadequate CSRF protection, enabling attackers to trick users into following malicious links or visiting compromised sites. By exploiting this vulnerability, attackers may send unauthorized requests to the affected device through the Device Manager interface, executing actions under the user's credentials. This poses significant security risks, as it can lead to unauthorized changes or actions on the devices managed by affected users.
Affected Version(s)
Cisco Industrial Ethernet 1000 Series Switches Cisco Industrial Ethernet 1000 Series Switches