Vulnslist

find the latest Cisco vulnerabilities

Cisco Prime Infrastructure Rogue AP SSID Cross-Site Scripting Vulnerability

Cisco-SA-20130531-CVE-2013-1247 · Medium · Published · Updated

A vulnerability in the wireless configuration module of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to insert scripts into the listing of rogue access points. The vulnerability is due to a failure to properly sanitize SSIDs before inserting them into the XML windowing table used to display the list of rogue access points. An attacker could exploit this vulnerability by using a script as the SSID of a rogue access point. A successful exploit could allow the attacker to to execute scripts in the browser of a user viewing the malicious SSID. Cisco has confirmed the vulnerability in a security notice; however, software updates are not available. To exploit this vulnerability, the attacker would likely need access to a trusted, internal network in order to use a malicious script as the SSID of a rogue access point or have the knowledge of whether rogue access points exist in the network. Customers are advised to review the bug reports in the "Vendor Announcements" section for a current list of affected versions.

Workarounds

Administrators are advised to contact the vendor regarding future updates and releases.

Administrators are advised to allow only trusted users to have network access.

For additional information about cross-site scripting attacks and the methods used to exploit these vulnerabilities, see the Cisco Applied Mitigation Bulletin Understanding Cross-Site Scripting (XSS) Threat Vectorshttp://www.cisco.com/en/US/products/cmb/cisco-amb-20060922-understanding-xss.html .

Administrators are advised to monitor affected systems.

CVEsCVE-2013-1247
Cisco Bug IDsCSCuf04356
CVSS ScoreBase 4.3
Base 4.3 AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:U/RC:C
Product Names From Source
Cisco Prime Infrastructure

CSAF Product Statuses

Product Status Source CVE Rows
Cisco Prime Infrastructure known_affected cisco_csaf CVE-2013-1247 1

Related Products

Product CVE Evidence
Cisco Prime Infrastructure CVE-2013-1247 Cisco OpenVuln