CVE-2017-3868: XSS
A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvc44344. Known Affected Releases: 6.0(0.0).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco UCS Directorto a version that resolves this vulnerability.Fixed in 6.0(0.0)Patch CSCvc44344
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3868?
CVE-2017-3868 has been rated as moderate in severity due to the potential for cross-site scripting attacks.
How do I fix CVE-2017-3868?
To remediate CVE-2017-3868, users should update Cisco UCS Director to a version that is not affected by this vulnerability.
Who is affected by CVE-2017-3868?
CVE-2017-3868 affects users of Cisco UCS Director version 6.0(0.0) and possibly other vulnerable versions.
What does CVE-2017-3868 exploit?
CVE-2017-3868 exploits the web-based management interface of Cisco UCS Director to allow for cross-site scripting attacks.
Can CVE-2017-3868 be exploited remotely?
Yes, CVE-2017-3868 can be exploited remotely by an unauthenticated attacker.