CVE-2017-6675
published 2017-06-13CVE-2017-6675: A vulnerability in the web interface of Cisco Industrial Network Director could allow an unauthenticated, remote attacker to conduct a reflected cross-site…
PriorityP425medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
0.91%
55.9th percentile
A vulnerability in the web interface of Cisco Industrial Network Director could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against an affected system. More Information: CSCvd25405. Known Affected Releases: 1.1(0.176).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | industrial_network_director | — | — |
| cisco | industrial_network_director | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gqrf-2pvg-fm63: A vulnerability in the web interface of Cisco Industrial Network Director could allow an unauthenticated, remote attacker to conduct a reflected cross
ghsa_unreviewed·2022-05-17
CVE-2017-6675 [MEDIUM] CWE-79 GHSA-gqrf-2pvg-fm63: A vulnerability in the web interface of Cisco Industrial Network Director could allow an unauthenticated, remote attacker to conduct a reflected cross
A vulnerability in the web interface of Cisco Industrial Network Director could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against an affected system. More Information: CSCvd25405. Known Affected Releases: 1.1(0.176).
Cisco
Cisco Industrial Network Director Cross-Site Scripting Vulnerability
vendor_cisco·2017-06-07·CVSS 6.1
CVE-2017-6675 [MEDIUM] CWE-79 Cisco Industrial Network Director Cross-Site Scripting Vulnerability
Cisco Industrial Network Director Cross-Site Scripting Vulnerability
A vulnerability in the web interface of Cisco Industrial Network Director could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against an affected system.
The vulnerability is due to insufficient validation of certain user-supplied input passed in the URL of an affected page. An attacker who can convince a user to follow a malicious link or visit an attacker-controlled website could cause arbitrary HTML or script code to be executed in the context of the affected site in the user’s browser. This could result in the attacker gaining the ability to disclose potentially sensitive information from the browser or modify the visual and operational conditions of the rendered
Cisco
Cisco Industrial Network Director Cross-Site Scripting Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-6675 Cisco Industrial Network Director Cross-Site Scripting Vulnerability
CVE-2017-6675: Cisco Industrial Network Director Cross-Site Scripting Vulnerability
A vulnerability in the web interface of Cisco Industrial Network Director could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against an affected system. The vulnerability is due to insufficient validation of certain user-supplied input passed in the URL of an affected page. An attacker who can convince a user to follow a malicious link or visit an attacker-controlled website could cause arbitrary HTML or script code to be executed in the context of the affected site in the user’s browser. This could result in the attacker gaining the ability to disclose potentially sensitive information from the browser or modify the visual and operational conditions of
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-06-13
Published