CVE-2018-15438: Cisco Prime Collaboration Assurance Cross-Site Request Forgery Vulnerability
A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to use a web browser to perform arbitrary actions with the privileges of the user on an affected system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15438?
CVE-2018-15438 is a vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance that could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system.
How does CVE-2018-15438 affect Cisco Prime Collaboration Assurance?
CVE-2018-15438 affects Cisco Prime Collaboration Assurance by exposing it to a cross-site request forgery (CSRF) vulnerability, which enables an attacker to perform unauthorized actions on the system.
What is the severity of CVE-2018-15438?
CVE-2018-15438 has a severity rating of medium, with a CVSS score of 6.5.
How can I fix CVE-2018-15438?
To fix CVE-2018-15438, apply the necessary updates or patches provided by Cisco Prime Collaboration Assurance.
Is there any additional information about CVE-2018-15438?
Yes, you can find additional information about CVE-2018-15438 on the following references: [SecurityFocus](http://www.securityfocus.com/bid/105670), [SecurityTracker](http://www.securitytracker.com/id/1041930), [Cisco Security Advisory](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181017-cpca-csrf).