CVE-2018-15402

Description

A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks. The vulnerability is due to improper validation of Origin headers on HTTP requests within the management interface. An attacker could exploit this vulnerability by convincing a targeted user to follow a URL to a malicious website. An exploit could allow the attacker to take actions within the software with the privileges of the targeted user or gain access to sensitive information.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.095

Associated Vulnerability

VulnerabilityOS Platform
Cisco Enterprise NFV Infrastructure Software Cross-Site Request Forgery Vulnerability For Cisco Enterprise NFV Infrastructure SoftwareNCM
Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-15402)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1700665Security Update for Cisco Enterprise NFV Infrastructure Software NFVIS-3.12.3

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234