CVE-2017-12225

medium
Published 2017-09-07 · Modified 2026-05-13
CVSS v3
6.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS v2
4.3
VIR risk
6.5

Description

A vulnerability in the web functionality of the Cisco Prime LAN Management Solution could allow an authenticated, remote attacker to hijack another user's administrative session, aka a Session Fixation Vulnerability. The vulnerability is due to the reuse of a preauthentication session token as part of the postauthentication session. An attacker could exploit this vulnerability by obtaining the presession token ID. An exploit could allow an attacker to hijack an existing user's session. Known Affected Releases 4.2(5). Cisco Bug IDs: CSCvf58392.

Predictions

Exploit likelihood
75%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@cisco.com — https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170906-prime-lms

vendor Authored 2026-05-27

Vendor advisory: psirt@cisco.com — https://quickview.cloudapps.cisco.com/quickview/bug/CSCvf58392

Application impact

VendorProductVersionsFixed
cisco ciscoprime_lan_management_solution4.2\(5\)

References

CWEs

CWE-287 CWE-384

Verify integrity in audit chain (admin only). AS-IS.