Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2017-6634 Details

Description

A vulnerability in the Device Manager web interface of Cisco Industrial Ethernet 1000 Series Switches 1.3 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected system. The vulnerability is due to insufficient CSRF protection by the Device Manager web interface. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link or visit an attacker-controlled website. A successful exploit could allow the attacker to submit arbitrary requests to an affected device via the Device Manager web interface and with the privileges of the user. Cisco Bug IDs: CSCvc88811.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-352Cross-Site Request Forgery (CSRF)[email protected]
CWE-352Cross-Site Request Forgery (CSRF)[email protected]

Affected Products

ProductVersions
cisco industrial ethernet 1000 series firmware
1.3_base

CPE

  • cpe:2.3:o:cisco:industrial_ethernet_1000_series_firmware:1.3_base:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cisco ie-1000-4p2s-lm
All versions

CPE

  • cpe:2.3:h:cisco:ie-1000-4p2s-lm:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cisco ie-1000-4t1t-lm
All versions

CPE

  • cpe:2.3:h:cisco:ie-1000-4t1t-lm:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cisco ie-1000-6t2t-lm
All versions

CPE

  • cpe:2.3:h:cisco:ie-1000-6t2t-lm:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cisco ie-1000-8p2s-lm
All versions

CPE

  • cpe:2.3:h:cisco:ie-1000-8p2s-lm:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

8 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2017-6634
NVD Published Date:
May 22, 2017
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2017-6634 Details - Not Deferred