VDB
CVE-2018-0097
CVE-2018-0097
PUBLISHED
CVSS 6.099999904632568 MEDIUM
A vulnerability in the web interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect. The vulnerability is due to improper input validation of the parameters in the HTTP request. An attacker could exploit this vulnerability by crafting an HTTP request that could cause the web application to redirect the request to a specific malicious URL. This vulnerability is known as an open redirect attack and is used in phishing attacks to get users to visit malicious sites without their knowledge. Cisco Bug IDs: CSCve37646.
EPSS 1.21% · 67.6th percentile
Risk Scores
CVSS 3.0
6.099999904632568
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
1.21%
67.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | prime_infrastructure | |
| n/a | Cisco Prime Infrastructure | Cisco Prime Infrastructure |
Timeline
- Jan 17, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 28, 2021 EPSS Score
- Dec 30, 2021 EPSS Score
- Mar 3, 2022 EPSS Score
- May 5, 2022 EPSS Score
- May 13, 2022 CVE Updated
- Jul 7, 2022 EPSS Score
- Nov 12, 2022 EPSS Score
- Jan 14, 2023 EPSS Score