The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

Computer vulnerabilities of Cisco Prime Infrastructure

computer vulnerability announce CVE-2018-15433

Cisco Prime Infrastructure: information disclosure via GET Request

Synthesis of the vulnerability

Impacted products: Prime Infrastructure.
Severity: 2/4.
Consequences: data reading.
Provenance: user account.
Confidence: confirmed by the editor (5/5).
Creation date: 04/10/2018.
Identifiers: CERTFR-2018-AVI-468, cisco-sa-20181003-prime-id, CSCvg93152, CVE-2018-15433, VIGILANCE-VUL-27407.

Description of the vulnerability

An attacker can bypass access restrictions to data via GET Request of Cisco Prime Infrastructure, in order to obtain sensitive information.
Complete Vigil@nce bulletin.... (Free trial)

computer vulnerability CVE-2018-15432

Cisco Prime Infrastructure: information disclosure via Server Backup

Synthesis of the vulnerability

Impacted products: Prime Infrastructure.
Severity: 2/4.
Consequences: data reading.
Provenance: user account.
Confidence: confirmed by the editor (5/5).
Creation date: 04/10/2018.
Identifiers: CERTFR-2018-AVI-468, cisco-sa-20181003-pi-id, CSCvg93148, CVE-2018-15432, VIGILANCE-VUL-27405.

Description of the vulnerability

An attacker can bypass access restrictions to data via Server Backup of Cisco Prime Infrastructure, in order to obtain sensitive information.
Complete Vigil@nce bulletin.... (Free trial)

computer vulnerability note CVE-2018-5391

Linux kernel: denial of service via FragmentSmack

Synthesis of the vulnerability

Impacted products: GAiA, SecurePlatform, CheckPoint Security Gateway, Cisco Aironet, IOS XE Cisco, Nexus by Cisco, Prime Collaboration Assurance, Prime Infrastructure, Cisco Router, Secure ACS, Cisco CUCM, Cisco UCS, Cisco Unified CCX, Cisco IP Phone, Cisco Wireless Controller, Debian, BIG-IP Hardware, TMOS, Junos Space, Linux, Windows 10, Windows 2008 R0, Windows 2008 R2, Windows 2012, Windows 2016, Windows 7, Windows 8, Windows RT, openSUSE Leap, Palo Alto Firewall PA***, PAN-OS, RHEL, SUSE Linux Enterprise Desktop, SLES, Symantec Content Analysis, ProxySG by Symantec, Synology DSM, Ubuntu, WindRiver Linux.
Severity: 2/4.
Consequences: denial of service on server, denial of service on service.
Provenance: internet client.
Confidence: confirmed by the editor (5/5).
Creation date: 16/08/2018.
Identifiers: ADV180022, CERTFR-2018-AVI-390, CERTFR-2018-AVI-392, CERTFR-2018-AVI-419, CERTFR-2018-AVI-457, CERTFR-2018-AVI-478, CERTFR-2018-AVI-533, cisco-sa-20180824-linux-ip-fragment, CVE-2018-5391, DLA-1466-1, DLA-1529-1, DSA-4272-1, FragmentSmack, JSA10917, K74374841, openSUSE-SU-2018:2404-1, openSUSE-SU-2018:2407-1, PAN-SA-2018-0012, RHSA-2018:2785-01, RHSA-2018:2791-01, RHSA-2018:2846-01, RHSA-2018:2924-01, RHSA-2018:2925-01, RHSA-2018:2933-01, RHSA-2018:2948-01, RHSA-2018:3083-01, RHSA-2018:3096-01, RHSA-2018:3459-01, RHSA-2018:3540-01, RHSA-2018:3586-01, RHSA-2018:3590-01, sk134253, SUSE-SU-2018:2344-1, SUSE-SU-2018:2374-1, SUSE-SU-2018:2380-1, SUSE-SU-2018:2381-1, SUSE-SU-2018:2596-1, SYMSA1467, Synology-SA-18:44, USN-3740-1, USN-3740-2, USN-3741-1, USN-3741-2, USN-3741-3, USN-3742-1, USN-3742-2, USN-3742-3, VIGILANCE-VUL-27009, VU#641765.

Description of the vulnerability

An attacker can generate a fatal error via FragmentSmack of the Linux kernel, in order to trigger a denial of service.
Complete Vigil@nce bulletin.... (Free trial)

computer vulnerability alert CVE-2018-0096

Cisco Prime Infrastructure: privilege escalation via Virtual Domain RBAC

Synthesis of the vulnerability

Impacted products: Prime Infrastructure.
Severity: 2/4.
Consequences: administrator access/rights, privileged access/rights.
Provenance: user account.
Confidence: confirmed by the editor (5/5).
Creation date: 18/01/2018.
Identifiers: cisco-sa-20180117-cpi, CSCvg36875, CVE-2018-0096, VIGILANCE-VUL-25116.

Description of the vulnerability

An attacker can bypass restrictions via Virtual Domain RBAC of Cisco Prime Infrastructure, in order to escalate his privileges.
Complete Vigil@nce bulletin.... (Free trial)

vulnerability CVE-2018-0097

Cisco Prime Infrastructure: open redirect

Synthesis of the vulnerability

An attacker can deceive the user of Cisco Prime Infrastructure, in order to redirect him to a malicious site.
Impacted products: Prime Infrastructure.
Severity: 1/4.
Consequences: user access/rights, data reading.
Provenance: internet client.
Confidence: confirmed by the editor (5/5).
Creation date: 18/01/2018.
Identifiers: cisco-sa-20180117-prime-infrastructure, CSCve37646, CVE-2018-0097, VIGILANCE-VUL-25110.

Description of the vulnerability

The Cisco Prime Infrastructure product offers a web service.

However, the web service accepts to redirect the victim with no warning, to an external site indicated by the attacker.

An attacker can therefore deceive the user of Cisco Prime Infrastructure, in order to redirect him to a malicious site.
Complete Vigil@nce bulletin.... (Free trial)

computer vulnerability alert CVE-2017-6782

Cisco Prime Infrastructure: Cross Site Scripting

Synthesis of the vulnerability

An attacker can trigger a Cross Site Scripting of Cisco Prime Infrastructure, in order to run JavaScript code in the context of the web site.
Impacted products: Prime Infrastructure.
Severity: 2/4.
Consequences: client access/rights.
Provenance: document.
Confidence: confirmed by the editor (5/5).
Creation date: 17/08/2017.
Identifiers: CERTFR-2017-AVI-269, cisco-sa-20170816-cpi, CSCve47074, CVE-2017-6782, VIGILANCE-VUL-23556.

Description of the vulnerability

The Cisco Prime Infrastructure product offers a web service.

However, it does not filter received data before inserting them in generated HTML documents.

An attacker can therefore trigger a Cross Site Scripting of Cisco Prime Infrastructure, in order to run JavaScript code in the context of the web site.
Complete Vigil@nce bulletin.... (Free trial)

computer vulnerability CVE-2017-6725

Cisco Prime Infrastructure: Cross Site Scripting

Synthesis of the vulnerability

An attacker can trigger a Cross Site Scripting of Cisco Prime Infrastructure, in order to run JavaScript code in the context of the web site.
Impacted products: Prime Infrastructure.
Severity: 2/4.
Consequences: client access/rights.
Provenance: document.
Confidence: confirmed by the editor (5/5).
Creation date: 22/06/2017.
Identifiers: CERTFR-2017-AVI-191, cisco-sa-20170621-piwf1, CSCuw65833, CSCuw65837, CVE-2017-6725, VIGILANCE-VUL-23065.

Description of the vulnerability

The Cisco Prime Infrastructure product offers a web service.

However, it does not filter received data before inserting them in generated HTML documents.

An attacker can therefore trigger a Cross Site Scripting of Cisco Prime Infrastructure, in order to run JavaScript code in the context of the web site.
Complete Vigil@nce bulletin.... (Free trial)

vulnerability note CVE-2017-6724

Cisco Prime Infrastructure: Cross Site Scripting

Synthesis of the vulnerability

An attacker can trigger a Cross Site Scripting of Cisco Prime Infrastructure, in order to run JavaScript code in the context of the web site.
Impacted products: Prime Infrastructure.
Severity: 2/4.
Consequences: client access/rights.
Provenance: document.
Confidence: confirmed by the editor (5/5).
Creation date: 22/06/2017.
Identifiers: CERTFR-2017-AVI-191, cisco-sa-20170621-piwf, CSCuw65843, CVE-2017-6724, VIGILANCE-VUL-23064.

Description of the vulnerability

The Cisco Prime Infrastructure product offers a web service.

However, it does not filter received data before inserting them in generated HTML documents.

An attacker can therefore trigger a Cross Site Scripting of Cisco Prime Infrastructure, in order to run JavaScript code in the context of the web site.
Complete Vigil@nce bulletin.... (Free trial)

vulnerability bulletin CVE-2017-6700

Cisco Prime Infrastructure: Cross Site Scripting

Synthesis of the vulnerability

An attacker can trigger a Cross Site Scripting of Cisco Prime Infrastructure, in order to run JavaScript code in the context of the web site.
Impacted products: Prime Infrastructure.
Severity: 2/4.
Consequences: client access/rights.
Provenance: document.
Confidence: confirmed by the editor (5/5).
Creation date: 22/06/2017.
Identifiers: CERTFR-2017-AVI-191, cisco-sa-20170621-piepnm4, CSCvc24620, CSCvc49586, CVE-2017-6700, VIGILANCE-VUL-23063.

Description of the vulnerability

The Cisco Prime Infrastructure product offers a web service.

However, it does not filter received data before inserting them in generated HTML documents.

An attacker can therefore trigger a Cross Site Scripting of Cisco Prime Infrastructure, in order to run JavaScript code in the context of the web site.
Complete Vigil@nce bulletin.... (Free trial)

vulnerability announce CVE-2017-6699

Cisco Prime Infrastructure: Cross Site Scripting

Synthesis of the vulnerability

An attacker can trigger a Cross Site Scripting of Cisco Prime Infrastructure, in order to run JavaScript code in the context of the web site.
Impacted products: Prime Infrastructure.
Severity: 2/4.
Consequences: client access/rights.
Provenance: document.
Confidence: confirmed by the editor (5/5).
Creation date: 22/06/2017.
Identifiers: CERTFR-2017-AVI-191, cisco-sa-20170621-piepnm3, CSCvc24616, CSCvc35363, CSCvc49574, CVE-2017-6699, VIGILANCE-VUL-23062.

Description of the vulnerability

The Cisco Prime Infrastructure product offers a web service.

However, it does not filter received data before inserting them in generated HTML documents.

An attacker can therefore trigger a Cross Site Scripting of Cisco Prime Infrastructure, in order to run JavaScript code in the context of the web site.
Complete Vigil@nce bulletin.... (Free trial)
Our database contains other pages. You can request a free trial to read them.

Display information about Cisco Prime Infrastructure: