Learn about CVE-2017-12225 affecting Cisco Prime LAN Management Solution version 4.2(5). Find out how remote attackers can exploit a Session Fixation Vulnerability to hijack administrative sessions and steps to mitigate the risk.
Cisco Prime LAN Management Solution is affected by a Session Fixation Vulnerability that allows a remote attacker to hijack an administrative session. The vulnerability affects version 4.2(5) and was identified by Cisco Bug IDs: CSCvf58392.
Understanding CVE-2017-12225
This CVE involves a flaw in the web functionality of Cisco Prime LAN Management Solution that can be exploited by authenticated remote attackers.
What is CVE-2017-12225?
The vulnerability in Cisco Prime LAN Management Solution allows an attacker to take control of another user's administrative session by reusing a session token.
The Impact of CVE-2017-12225
Technical Details of CVE-2017-12225
Cisco Prime LAN Management Solution is affected by a Session Fixation Vulnerability.
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Immediate Steps to Take:
Long-Term Security Practices:
Patching and Updates: