Cross-Site Request Forgery in Cisco UCS Director and IMC Supervisor Software
CVE-2018-0148
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 22 February 2018
Summary
A vulnerability exists in the web-based management interface of Cisco UCS Director Software and Cisco Integrated Management Controller (IMC) Supervisor Software. This flaw could allow an unauthenticated remote attacker to execute a cross-site request forgery (CSRF) attack, enabling them to perform arbitrary actions on the affected system. The vulnerability arises from a lack of adequate CSRF protection in the web interface. An attacker could exploit this vulnerability by deceiving a user into clicking a malicious link, which could allow the attacker to take actions on the system using the user's privileges, potentially compromising the security and integrity of the affected systems.
Affected Version(s)
Cisco UCS Director and Cisco Integrated Management Controller Supervisor Cisco UCS Director and Cisco Integrated Management Controller Supervisor
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved