CVE-2017-3869: Medium severity cisco Prime Infrastructure vulnerability
Published Mar 17, 2017
·Updated
An API Credentials Management vulnerability in the APIs for Cisco Prime Infrastructure could allow an authenticated, remote attacker to access an API that should be restricted to a privileged user. The attacker needs to have valid credentials. More Information: CSCuy36192. Known Affected Releases: 3.1(1) 3.1(1).
Affected Software
1 affected component
cisco Prime Infrastructure=3.1\(1\)
Event History
Mar 17, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Data Sourced
via NVD·10:59 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-3869?
CVE-2017-3869 is classified as a medium severity vulnerability.
2
How do I fix CVE-2017-3869?
To remediate CVE-2017-3869, update Cisco Prime Infrastructure to the latest patched version as recommended by Cisco.
3
What types of attacks can CVE-2017-3869 facilitate?
CVE-2017-3869 can allow an authenticated attacker to gain unauthorized access to restricted APIs.
4
Which versions of Cisco Prime Infrastructure are affected by CVE-2017-3869?
CVE-2017-3869 specifically affects Cisco Prime Infrastructure version 3.1(1).
5
What are the requirements for exploiting CVE-2017-3869?
An attacker must have valid credentials to exploit CVE-2017-3869.