First published: Wed Feb 22 2017(Updated: )
A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. Affected Products: Cisco Prime Collaboration Assurance software versions 11.0, 11.1, and 11.5 are vulnerable. Cisco Prime Collaboration Assurance software versions prior to 11.0 are not vulnerable. More Information: CSCvc77783. Known Affected Releases: 11.5(0).
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Collaboration Assurance | =11.0.0 | |
Cisco Prime Collaboration Assurance | =11.1.0 | |
Cisco Prime Collaboration Assurance | =11.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3845 is categorized as a high-severity vulnerability due to the potential for remote attackers to perform cross-site scripting attacks.
To mitigate CVE-2017-3845, upgrade to a non-vulnerable version of Cisco Prime Collaboration Assurance as detailed in Cisco's security advisory.
CVE-2017-3845 affects users of Cisco Prime Collaboration Assurance version 11.0.0, 11.1.0, and 11.5.0.
CVE-2017-3845 allows unauthenticated remote attackers to conduct cross-site scripting (XSS) attacks.
No, authentication is not required to exploit CVE-2017-3845, making it particularly dangerous for affected users.