CVE-2017-6700 β€” Cross-site Scripting in Cisco Prime Infrastructure

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 42.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 4
Latest updateMay 17

Description

A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an unauthenticated, remote attacker to conduct a Document Object Model (DOM) based (environment or client-side) cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvc24620 CSCvc49586. Known Affected Releases: 3.1(1) 2.0(4.0.45B).

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

β–ΆNVDcisco/prime_infrastructure2.0\(4.0.45b\), 3.1\(1\)+1

πŸ”΄Vulnerability Details

2
GHSA
GHSA-wq3q-rvw4-79x9: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow a↗2022-05-17
β–Ά
CVEList
CVE-2017-6700: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow a↗2017-07-04
β–Ά

πŸ“‹Vendor Advisories

1
Cisco
Cisco Prime Infrastructure and Evolved Programmable Network Manager DOM Cross-Site Scripting Vulnerability↗2017-06-21
β–Ά
CVE-2017-6700 β€” Cross-site Scripting in Cisco | cvebase