VYPR
Medium severity6.1NVD Advisory· Published Apr 7, 2017· Updated May 13, 2026

CVE-2017-3848

CVE-2017-3848

Description

A vulnerability in the HTTP web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected system. More Information: CSCuw63001 CSCuw63003. Known Affected Releases: 2.2(2). Known Fixed Releases: 3.1(0.0).

Affected products

2
  • cpe:2.3:a:cisco:prime_infrastructure:2.2\(2\):*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:cisco:prime_infrastructure:2.2\(2\):*:*:*:*:*:*:*
    • cpe:2.3:a:cisco:prime_infrastructure:3.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.