CVE-2017-12225
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the web functionality of the Cisco Prime LAN Management Solution could allow an authenticated, remote attacker to hijack another user's administrative session, aka a Session Fixation Vulnerability. The vulnerability is due to the reuse of a preauthentication session token as part of the postauthentication session. An attacker could exploit this vulnerability by obtaining the presession token ID. An exploit could allow an attacker to hijack an existing user's session. Known Affected Releases 4.2(5). Cisco Bug IDs: CSCvf58392.
Una vulnerabilidad en la funcionalidad web de Cisco Prime LAN Management Solution podría permitir que un atacante remoto autenticado secuestre la sesión administrativa de otro usuario. Esto también se conoce como vulnerabilidad de fijación de sesión. Esta vulnerabilidad se debe a la reutilización de un token de la sesión de preautenticación como parte de la sesión de postautenticación. Un atacante podría explotar esta vulnerabilidad obteniendo el ID del token de presesión. Si se explota esta vulnerabilidad, un atacante podría secuestrar la sesión de un usuario. Versiones afectadas conocidas 4.2(5): Cisco Bug IDs: CSCvf58392.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-08-03 CVE Reserved
- 2017-09-07 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
- CWE-384: Session Fixation
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1039285 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Prime Lan Management Solution Search vendor "Cisco" for product "Prime Lan Management Solution" | 4.2\(5\) Search vendor "Cisco" for product "Prime Lan Management Solution" and version "4.2\(5\)" | - |
Affected
|