Vulnerability record · CVE-2017-12225 · published 7 September 2017
CVE-2017-12225: Cisco prime lan management solution improper authentication vulnerability
Cisco · Prime Lan Management Solution
A vulnerability in the web functionality of the Cisco Prime LAN Management Solution could allow an authenticated, remote attacker to hijack another user's administrative session, aka a Session Fixation Vulnerability. The vulnerability is due to the reuse of a preauthentication session token as part of the postauthentication session. An attacker could exploit this vulnerability by obtaining the presession token ID. An exploit could allow an attacker to hijack an existing user's session. Known Affected Releases 4.2(5). Cisco Bug IDs: CSCvf58392.
Description
A vulnerability in the web functionality of the Cisco Prime LAN Management Solution could allow an authenticated, remote attacker to hijack another user's administrative session, aka a Session Fixation Vulnerability. The vulnerability is due to the reuse of a preauthentication session token as part of the postauthentication session. An attacker could exploit this vulnerability by obtaining the presession token ID. An exploit could allow an attacker to hijack an existing user's session. Known Affected Releases 4.2(5). Cisco Bug IDs: CSCvf58392.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securitytracker.com/id/1039285 | Third Party AdvisoryVDB Entry |
| https://quickview.cloudapps.cisco.com/quickview/bug/CSCvf58392 | Vendor Advisory |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170906-prime-lms | Vendor Advisory |
| http://www.securitytracker.com/id/1039285 | Third Party AdvisoryVDB Entry |
| https://quickview.cloudapps.cisco.com/quickview/bug/CSCvf58392 | Vendor Advisory |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170906-prime-lms | Vendor Advisory |
Track CVE-2017-12225 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-12225), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.