CVE-2013-5482: Medium severity cisco prime lan management solution vulnerability
Cisco Prime LAN Management Solution (LMS) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCug77823.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5482?
CVE-2013-5482 is classified as a medium severity vulnerability affecting Cisco Prime LAN Management Solution.
How do I fix CVE-2013-5482?
To fix CVE-2013-5482, upgrade to the latest version of Cisco Prime LAN Management Solution provided by Cisco.
What type of attacks can CVE-2013-5482 facilitate?
CVE-2013-5482 can facilitate clickjacking and potentially other attacks via crafted websites.
Which versions of Cisco Prime LAN Management Solution are affected by CVE-2013-5482?
CVE-2013-5482 affects all versions of Cisco Prime LAN Management Solution prior to the security updates.
Is CVE-2013-5482 a client-side or server-side vulnerability?
CVE-2013-5482 is primarily a client-side vulnerability related to cross-frame scripting.