Junglewise Threat Intelligence

CVE-2016-9222: Cisco NetFlow Generation Appliance XSS in management interface

CVE-2016-9222 · Severity: medium · CVSS 6.1 · Published 2017-01-26

Vendors: Cisco.

Executive brief

A vulnerability in the Cisco NetFlow Generation Appliance's management interface could allow an attacker to perform a cross-site scripting (XSS) attack. By tricking an administrator into clicking a malicious link, an attacker could execute unauthorized scripts in the user's browser. This could lead to the theft of session information or unauthorized actions performed on behalf of the logged-in user.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the web-based management interface of Cisco NetFlow Generation Appliance due to insufficient validation of user-supplied input. An unauthenticated remote attacker can exploit this by persuading a targeted user to click a specially crafted URL. If successful, the attacker can execute arbitrary script code in the context of the victim's browser session, potentially allowing for the theft of sensitive browser-based information or session cookies. The vulnerability is identified by Cisco Bug ID CSCvb15229 and affects release 1.0(2).

Affected products

  • Cisco NetFlow Generation Appliance 1.0(2)

Timeline

  • 2017-01-18: advisory: Initial public release by Cisco
  • 2017-01-26: disclosed: NVD publication date

References