PT-2018-8752 · Cisco · Cisco Prime Collaboration Provisioning

Published

2018-06-07

·

Updated

2019-10-09

·

CVE-2018-0322

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Prime Collaboration Provisioning (PCP) versions 12.1 and prior
Description A vulnerability in the web management interface could allow an authenticated, remote attacker to modify sensitive data associated with arbitrary accounts on an affected device. This is due to a failure to enforce access restrictions on certain roles assigned to authenticated users, potentially allowing an attacker to modify critical attributes of higher-privileged accounts and gain elevated privileges on the device.
Recommendations For Cisco Prime Collaboration Provisioning (PCP) versions 12.1 and prior, update to a version later than 12.1 to resolve the issue.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-0322

Affected Products

Cisco Prime Collaboration Provisioning