6.8
CVSSv2

CVE-2014-7996

Published: 18/11/2014 Updated: 08/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Integrated Management Controller in Cisco Unified Computing System allows remote malicious users to hijack the authentication of arbitrary users, aka Bug ID CSCuq45477.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified computing system -

Vendor Advisories

A vulnerability in the web framework code of Cisco Integrated Management Controller could allow an unauthenticated, remote attacker to perform a cross-site request forgery (CSRF) attack The vulnerability is due to insufficient CSRF protections An attacker could exploit this vulnerability by convincing the user of the affected system to follow a ...