PT-2018-8752 · Cisco · Cisco Prime Collaboration Provisioning
Published
2018-06-07
·
Updated
2019-10-09
·
CVE-2018-0322
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Prime Collaboration Provisioning (PCP) versions 12.1 and prior
Description
A vulnerability in the web management interface could allow an authenticated, remote attacker to modify sensitive data associated with arbitrary accounts on an affected device. This is due to a failure to enforce access restrictions on certain roles assigned to authenticated users, potentially allowing an attacker to modify critical attributes of higher-privileged accounts and gain elevated privileges on the device.
Recommendations
For Cisco Prime Collaboration Provisioning (PCP) versions 12.1 and prior, update to a version later than 12.1 to resolve the issue.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Prime Collaboration Provisioning