PT-2017-17295 · Cisco · Cisco Prime Collaboration Provisioning Tool

Published

2017-08-07

·

Updated

2019-10-09

·

CVE-2017-6756

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Prime Collaboration Provisioning Tool versions prior to 12.2
Description A lack of defense against cross-site request forgery (CSRF) attacks in the Web UI Application could allow an unauthenticated, remote attacker to execute unwanted actions by forcing the user's browser to perform any action authorized for that user.
Recommendations For versions prior to 12.2, update to a version that includes the fix for Cisco Bug ID CSCvc90280 to prevent cross-site request forgery (CSRF) attacks. As a temporary workaround, consider implementing additional CSRF protection measures to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6756

Affected Products

Cisco Prime Collaboration Provisioning Tool