ID

VAR-201711-0343


CVE

CVE-2017-12348


TITLE

Cisco UCS Central Software cross-site scripting vulnerability

Trust: 1.4

sources: JVNDB: JVNDB-2017-010407 // CNNVD: CNNVD-201711-1217

DESCRIPTION

Multiple vulnerabilities in the web-based management interface of Cisco UCS Central Software could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected interface or hijack a valid session ID from a user of the affected interface. Cisco Bug IDs: CSCvf71978, CSCvf71986. Cisco UCS Central The software contains a cross-site scripting vulnerability. Vendors have confirmed this vulnerability Bug ID CSCvf71978 and CSCvf71986 It is released as.Information may be obtained and information may be altered. An attacker may leverage these issues to hijack an arbitrary session and gain unauthorized access to the affected application or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks. Cisco UCS Central Software is a set of Cisco UCS (Unified Computing System) resource management and monitoring solutions for global Cisco UCS (Unified Computing System) resources

Trust: 1.98

sources: NVD: CVE-2017-12348 // JVNDB: JVNDB-2017-010407 // BID: 102018 // VULHUB: VHN-102861

AFFECTED PRODUCTS

vendor:ciscomodel:unified computing system central softwarescope:eqversion:2.2\(1a\)a

Trust: 1.6

vendor:ciscomodel:unified computing system central softwarescope: - version: -

Trust: 0.8

vendor:ciscomodel:ucs central software 2.2 ascope: - version: -

Trust: 0.3

sources: BID: 102018 // JVNDB: JVNDB-2017-010407 // CNNVD: CNNVD-201711-1217 // NVD: CVE-2017-12348

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-12348
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-12348
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201711-1217
value: MEDIUM

Trust: 0.6

VULHUB: VHN-102861
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2017-12348
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-102861
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-12348
baseSeverity: MEDIUM
baseScore: 5.4
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.3
impactScore: 2.7
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-102861 // JVNDB: JVNDB-2017-010407 // CNNVD: CNNVD-201711-1217 // NVD: CVE-2017-12348

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-102861 // JVNDB: JVNDB-2017-010407 // NVD: CVE-2017-12348

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201711-1217

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201711-1217

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-010407

PATCH

title:cisco-sa-20171129-ucs-centralurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171129-ucs-central

Trust: 0.8

title:Cisco UCS Central Software Fixes for cross-site scripting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=76835

Trust: 0.6

sources: JVNDB: JVNDB-2017-010407 // CNNVD: CNNVD-201711-1217

EXTERNAL IDS

db:NVDid:CVE-2017-12348

Trust: 2.8

db:BIDid:102018

Trust: 2.0

db:SECTRACKid:1039924

Trust: 1.7

db:JVNDBid:JVNDB-2017-010407

Trust: 0.8

db:CNNVDid:CNNVD-201711-1217

Trust: 0.7

db:VULHUBid:VHN-102861

Trust: 0.1

sources: VULHUB: VHN-102861 // BID: 102018 // JVNDB: JVNDB-2017-010407 // CNNVD: CNNVD-201711-1217 // NVD: CVE-2017-12348

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20171129-ucs-central

Trust: 2.0

url:http://www.securityfocus.com/bid/102018

Trust: 1.7

url:http://www.securitytracker.com/id/1039924

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-12348

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-12348

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-102861 // BID: 102018 // JVNDB: JVNDB-2017-010407 // CNNVD: CNNVD-201711-1217 // NVD: CVE-2017-12348

CREDITS

Indrajith.A.N

Trust: 0.3

sources: BID: 102018

SOURCES

db:VULHUBid:VHN-102861
db:BIDid:102018
db:JVNDBid:JVNDB-2017-010407
db:CNNVDid:CNNVD-201711-1217
db:NVDid:CVE-2017-12348

LAST UPDATE DATE

2025-04-20T23:12:45.607000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-102861date:2019-10-09T00:00:00
db:BIDid:102018date:2017-12-19T22:01:00
db:JVNDBid:JVNDB-2017-010407date:2017-12-13T00:00:00
db:CNNVDid:CNNVD-201711-1217date:2019-10-17T00:00:00
db:NVDid:CVE-2017-12348date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:VULHUBid:VHN-102861date:2017-11-30T00:00:00
db:BIDid:102018date:2017-11-29T00:00:00
db:JVNDBid:JVNDB-2017-010407date:2017-12-13T00:00:00
db:CNNVDid:CNNVD-201711-1217date:2017-12-01T00:00:00
db:NVDid:CVE-2017-12348date:2017-11-30T09:29:00.933