CVE-2017-3848 is a cross-site scripting (XSS) vulnerability in the HTTP web-based management interface of Cisco Prime Infrastructure, specifically affecting version 2.2(2). This medium-severity vulnerability (CVSS 6.1) allows an unauthenticated, remote attacker to execute malicious scripts in a user's browser due to improper input validation (CWE-79). While there are no known public exploits, Metasploit modules, or Nuclei templates, and it is not listed in the KEV catalog, the vulnerability could lead to information disclosure or session hijacking. There is no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2\(2\)CPE matchmatch criteria | cpe:2.3:a:cisco:prime_infrastructure:2.2\(2\):*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:cisco:prime_infrastructure:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.