Cisco Security Manager CVE-2014-3267 Cross Site Request Forgery Vulnerability
BID:67550
Info
Cisco Security Manager CVE-2014-3267 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 67550 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3267 |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2014 12:00AM |
| Updated: | Jul 22 2014 06:19AM |
| Credit: | Cisco |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco Security Manager CVE-2014-3267 Cross Site Request Forgery Vulnerability
Cisco Security Manager is prone to a cross-site request-forgery vulnerability because the application does not properly validate HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions in the context of the affected user. Other attacks are also possible.
This issue is being tracked by Cisco bug IDs CSCuo46427 and CSCup26931.
Cisco Security Manager is prone to a cross-site request-forgery vulnerability because the application does not properly validate HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions in the context of the affected user. Other attacks are also possible.
This issue is being tracked by Cisco bug IDs CSCuo46427 and CSCup26931.
Exploit / POC
Cisco Security Manager CVE-2014-3267 Cross Site Request Forgery Vulnerability
To exploit the issue an attacker must entice a user into visiting a malicious site.
To exploit the issue an attacker must entice a user into visiting a malicious site.
Solution / Fix
Cisco Security Manager CVE-2014-3267 Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco Security Manager CVE-2014-3267 Cross Site Request Forgery Vulnerability
References:
References:
- Cisco Homepage (Cisco )