First published: Fri Mar 17 2017(Updated: )
A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvc44344. Known Affected Releases: 6.0(0.0).
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Computing System Director | =6.0\(0.0\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3868 has been rated as moderate in severity due to the potential for cross-site scripting attacks.
To remediate CVE-2017-3868, users should update Cisco UCS Director to a version that is not affected by this vulnerability.
CVE-2017-3868 affects users of Cisco UCS Director version 6.0(0.0) and possibly other vulnerable versions.
CVE-2017-3868 exploits the web-based management interface of Cisco UCS Director to allow for cross-site scripting attacks.
Yes, CVE-2017-3868 can be exploited remotely by an unauthenticated attacker.