cisco-sa-ios-webui-HfwnRgk: Cisco IOS and IOS XE Software Web UI Cross-Site Request Forgery Vulnerability
A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system through the web UI.This vulnerability is due to incorrectly accepting
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-ios-webui-HfwnRgk?
The severity of cisco-sa-ios-webui-HfwnRgk is categorized as high, indicating a significant risk level.
How do I fix cisco-sa-ios-webui-HfwnRgk?
To mitigate cisco-sa-ios-webui-HfwnRgk, you should upgrade to a fixed software version as specified in the Cisco advisory.
What systems are affected by cisco-sa-ios-webui-HfwnRgk?
cisco-sa-ios-webui-HfwnRgk affects Cisco IOS Software and Cisco IOS XE Software.
What kind of attack can cisco-sa-ios-webui-HfwnRgk facilitate?
cisco-sa-ios-webui-HfwnRgk can facilitate a cross-site request forgery (CSRF) attack.
Is cisco-sa-ios-webui-HfwnRgk exploitable without authentication?
Yes, cisco-sa-ios-webui-HfwnRgk can be exploited by an unauthenticated, remote attacker.