CVE-2017-12253: CSRF
A vulnerability in the Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to execute unwanted actions. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker could exploit this vulnerability by tricking the user of a web application into executing an adverse action. Cisco Bug IDs: CSCve76872.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12253?
CVE-2017-12253 has been classified as a high severity vulnerability due to its potential for unauthorized remote code execution.
How do I fix CVE-2017-12253?
To fix CVE-2017-12253, users should update to the latest patched version of Cisco Unified Intelligence Center.
What are the potential impacts of exploiting CVE-2017-12253?
Exploiting CVE-2017-12253 could allow an attacker to execute unwanted actions on behalf of authenticated users.
Who is affected by CVE-2017-12253?
CVE-2017-12253 affects users of Cisco Unified Intelligence Center version 11.5(1) who do not have proper CSRF protection implemented.
Is authentication required to exploit CVE-2017-12253?
No, CVE-2017-12253 can be exploited by an unauthenticated remote attacker.