CVE-2018-0097Open Redirect in Cisco Prime Infrastructure

CWE-601Open Redirect4 documents4 sources
Severity
6.1MEDIUMNVD
EPSS
0.3%
top 51.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 18
Latest updateMay 13

Description

A vulnerability in the web interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect. The vulnerability is due to improper input validation of the parameters in the HTTP request. An attacker could exploit this vulnerability by crafting an HTTP request that could cause the web application to redirect the request to a specific malicious URL. This vulnerability is known as an open redirect attack and is u

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

CVEListV5cisco/cisco_prime_infrastructureCisco Prime Infrastructure

🔴Vulnerability Details

2
GHSA
GHSA-2fp5-7g39-82f7: A vulnerability in the web interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious w2022-05-13
CVEList
CVE-2018-0097: A vulnerability in the web interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious w2018-01-18

📋Vendor Advisories

1
Cisco
Cisco Prime Infrastructure Open Redirect Vulnerability2018-01-17
CVE-2018-0097 — Open Redirect in Cisco | cvebase