First published: Thu May 05 2016(Updated: )
Open redirect vulnerability in Cisco Prime Collaboration Assurance Software 10.5 through 11.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCuu34121.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Collaboration Assurance | =10.5.0 | |
Cisco Prime Collaboration Assurance | =10.5.1 | |
Cisco Prime Collaboration Assurance | =10.6.0 | |
Cisco Prime Collaboration Assurance | =11.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1392 has been categorized as a moderate severity vulnerability due to the risk of unauthorized redirection and potential phishing attacks.
To mitigate CVE-2016-1392, update Cisco Prime Collaboration Assurance Software to a version that is not affected, such as version 11.1.0 or later.
CVE-2016-1392 affects Cisco Prime Collaboration Assurance versions 10.5.0, 10.5.1, 10.6.0, and 11.0.0.
CVE-2016-1392 can be exploited to perform phishing attacks by redirecting users to arbitrary malicious websites.
Yes, CVE-2016-1392 allows remote attackers to exploit the vulnerability without needing physical access to the vulnerable system.