Cross-Site Scripting Flaw in Cisco Prime Infrastructure and Evolved Programmable Network Manager
CVE-2017-6700
6.1MEDIUM
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 4 July 2017
Summary
A vulnerability exists in the web-based management interface of Cisco Prime Infrastructure and Evolved Programmable Network Manager, allowing remote attackers to execute client-side cross-site scripting (XSS) attacks. An unauthenticated attacker could exploit this flaw to manipulate the Document Object Model (DOM), leading to the potential execution of arbitrary scripts in the context of affected users. Proper security measures and timely updates are essential to mitigate the risk associated with this vulnerability.
Affected Version(s)
Cisco Prime Infrastructure and Evolved Programmable Network Manager Cisco Prime Infrastructure and Evolved Programmable Network Manager
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved