CVE-2017-12221: XSS
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input by the affected software. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code in the context of the affected system. Cisco Bug IDs: CSCvc38983.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12221?
CVE-2017-12221 has a severity rating of medium due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2017-12221?
To fix CVE-2017-12221, ensure that you apply the latest patches provided by Cisco for the affected Firepower Management Center software.
Who is affected by CVE-2017-12221?
CVE-2017-12221 affects users of the Cisco Secure Firewall Management Center and Cisco FirePOWER Management Center software.
What kind of attack can be executed due to CVE-2017-12221?
CVE-2017-12221 allows an authenticated attacker to execute cross-site scripting (XSS) attacks on users of the web interface.
Is user authentication required to exploit CVE-2017-12221?
Yes, CVE-2017-12221 requires user authentication for an attacker to exploit the vulnerability.