4.7
CVSSv3

CVE-2018-15423

Published: 05/10/2018 Updated: 16/09/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 4.7 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A vulnerability in the web UI of Cisco HyperFlex Software could allow an unauthenticated, remote malicious user to affect the integrity of a device via a clickjacking attack. The vulnerability is due to insufficient input validation of iFrame data in HTTP requests that are sent to an affected device. An attacker could exploit this vulnerability by sending crafted HTTP packets with malicious iFrame data. A successful exploit could allow the malicious user to perform a clickjacking attack where the user is tricked into clicking a malicious link.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco hyperflex hx data platform 3.0\\(1a\\)

cisco hyperflex hx data platform 2.6\\(1d\\)

Vendor Advisories

A vulnerability in the web UI of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack The vulnerability is due to insufficient input validation of iFrame data in HTTP requests that are sent to an affected device An attacker could exploit this vulnerability by sendin ...