First published: Thu Sep 21 2017(Updated: )
A vulnerability in the Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to execute unwanted actions. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker could exploit this vulnerability by tricking the user of a web application into executing an adverse action. Cisco Bug IDs: CSCve76872.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Intelligence Center | =11.5\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12253 has been classified as a high severity vulnerability due to its potential for unauthorized remote code execution.
To fix CVE-2017-12253, users should update to the latest patched version of Cisco Unified Intelligence Center.
Exploiting CVE-2017-12253 could allow an attacker to execute unwanted actions on behalf of authenticated users.
CVE-2017-12253 affects users of Cisco Unified Intelligence Center version 11.5(1) who do not have proper CSRF protection implemented.
No, CVE-2017-12253 can be exploited by an unauthenticated remote attacker.