Multiple Vulnerabilities in Cisco Data Center Network Manager Software

cisco-sa-20171129-dcnm · Medium · Published · Updated

Data: Cisco advisories · Cisco CSAF · NVD CVEs · NVD CPEs · CISA KEV · EPSS

Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client interface, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the “Details” section of this security advisory. There are no workarounds that address these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171129-dcnm

Workarounds

There are no workarounds that address these vulnerabilities.

CVEsCVE-2017-12343, CVE-2017-12344, CVE-2017-12345, CVE-2017-12346, CVE-2017-12347
Cisco Bug IDsCSCvf40477 , CSCvf63150 , CSCvf68218 , CSCvf68235 , CSCvf68247
CVSS ScoreBase 4.7
Base 4.7 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N/E:X/RL:X/RC:X
Base 6.1 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:X/RL:X/RC:X
Base 4.3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:X/RL:X/RC:X

Products with public affected evidence