First published: Mon May 22 2017(Updated: )
A vulnerability in the Device Manager web interface of Cisco Industrial Ethernet 1000 Series Switches 1.3 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected system. The vulnerability is due to insufficient CSRF protection by the Device Manager web interface. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link or visit an attacker-controlled website. A successful exploit could allow the attacker to submit arbitrary requests to an affected device via the Device Manager web interface and with the privileges of the user. Cisco Bug IDs: CSCvc88811.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Industrial Ethernet 1000 Series Firmware | =1.3_base | |
Cisco IE 1000 Series Switches | ||
Cisco IE 1000-4T1T-LM | ||
Cisco IE-1000-6T2T-LM | ||
Cisco IE 1000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6634 has a high severity rating due to its potential to allow unauthenticated remote attackers to perform CSRF attacks.
To mitigate CVE-2017-6634, ensure that your Cisco Industrial Ethernet 1000 Series Switches firmware is updated to a version that addresses the CSRF vulnerability.
CVE-2017-6634 facilitates a cross-site request forgery (CSRF) attack against users of affected systems.
CVE-2017-6634 affects the Cisco Industrial Ethernet 1000 Series Switches running firmware version 1.3.
No, exploitation of CVE-2017-6634 does not require authentication, making it particularly critical.