CVE-2017-3845: XSS
A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. Affected Products: Cisco Prime Collaboration Assurance software versions 11.0, 11.1, and 11.5 are vulnerable. Cisco Prime Collaboration Assurance software versions prior to 11.0 are not vulnerable. More Information: CSCvc77783. Known Affected Releases: 11.5(0).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Prime Collaboration Assuranceto a version that resolves this vulnerability.Fixed in 11.0Patch CSCvc77783 - Upgrade
Upgrade
Cisco Prime Collaboration Assuranceto a version that resolves this vulnerability.Fixed in 11.1Patch CSCvc77783 - Upgrade
Upgrade
Cisco Prime Collaboration Assuranceto a version that resolves this vulnerability.Fixed in 11.5(0)Patch CSCvc77783
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3845?
CVE-2017-3845 is categorized as a high-severity vulnerability due to the potential for remote attackers to perform cross-site scripting attacks.
How do I fix CVE-2017-3845?
To mitigate CVE-2017-3845, upgrade to a non-vulnerable version of Cisco Prime Collaboration Assurance as detailed in Cisco's security advisory.
Who is affected by CVE-2017-3845?
CVE-2017-3845 affects users of Cisco Prime Collaboration Assurance version 11.0.0, 11.1.0, and 11.5.0.
What type of attack does CVE-2017-3845 allow?
CVE-2017-3845 allows unauthenticated remote attackers to conduct cross-site scripting (XSS) attacks.
Is authentication required to exploit CVE-2017-3845?
No, authentication is not required to exploit CVE-2017-3845, making it particularly dangerous for affected users.