CVE-2017-3869

MEDIUM

Cisco Prime Infrastructure - Auth Bypass

Title source: llm
STIX 2.1

Description

An API Credentials Management vulnerability in the APIs for Cisco Prime Infrastructure could allow an authenticated, remote attacker to access an API that should be restricted to a privileged user. The attacker needs to have valid credentials. More Information: CSCuy36192. Known Affected Releases: 3.1(1) 3.1(1).

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96931
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038048

Scores

CVSS v3 5.4
EPSS 0.0096
EPSS Percentile 57.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

Status published
Products (2)
cisco/prime_infrastructure 3.1\(1\)
n/a/Cisco Prime Infrastructure Cisco Prime Infrastructure
Published Mar 17, 2017
Tracked Since Feb 18, 2026