First published: Fri Feb 27 2015(Updated: )
Cross-site request forgery (CSRF) vulnerability in the web GUI in Cisco Application Networking Manager (ANM), and Device Manager (DM) on Cisco 4710 Application Control Engine (ACE) appliances, allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuo99753.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Application Networking Manager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0651 is classified as a moderate severity vulnerability due to the potential for authentication hijacking.
To mitigate CVE-2015-0651, you should apply the latest security patches provided by Cisco for the affected products.
CVE-2015-0651 affects users of the Cisco Application Networking Manager and Device Manager on Cisco 4710 Application Control Engine appliances.
CVE-2015-0651 is a cross-site request forgery (CSRF) vulnerability.
An attacker exploiting CVE-2015-0651 could hijack the authentication of arbitrary users on the affected devices.