cisco-sa-20151008-pca1

Cisco Prime Collaboration Assurance Cross-Site Request Forgery Vulnerability

Medium · Updated · Cisco

1 product with CSAF evidence

A vulnerability in the web interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web interface. The vulnerability is due to insufficient CSRF protections. An attacker could exploit this vulnerability by persuading a user of an affected system to follow a crafted link or visit an attacker-controlled website. A successful exploit could allow an attacker to submit arbitrary requests to the affected system via a web browser and with the privileges of the user. Cisco released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.