CVE-2017-3848: XSS
A vulnerability in the HTTP web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected system. More Information: CSCuw63001 CSCuw63003. Known Affected Releases: 2.2(2). Known Fixed Releases: 3.1(0.0).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Prime Infrastructureto a version that resolves this vulnerability.Fixed in 3.1(0.0)
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3848?
CVE-2017-3848 is rated as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2017-3848?
To fix CVE-2017-3848, upgrade to the latest versions of Cisco Prime Infrastructure 2.2(3) or 3.0(1) or later.
What impact does CVE-2017-3848 have on users?
CVE-2017-3848 allows an unauthenticated attacker to execute malicious scripts in the context of an affected user's session.
Which versions of Cisco Prime Infrastructure are affected by CVE-2017-3848?
CVE-2017-3848 affects Cisco Prime Infrastructure versions 2.2(2) and 3.0.
Is CVE-2017-3848 a remote or local vulnerability?
CVE-2017-3848 is a remote vulnerability that can be exploited without physical access to the affected system.