PT-2018-8763 · Cisco · Cisco Prime Collaboration Provisioning

Published

2018-06-07

·

Updated

2019-10-09

·

CVE-2018-0335

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Prime Collaboration Provisioning (affected versions not specified)
Description A vulnerability in the web portal authentication process could allow an unauthenticated, local attacker to view sensitive data due to improper logging of authentication data. An attacker could exploit this by monitoring a specific world-readable file for authentication data, including cleartext passwords, potentially gaining authentication information for other users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Information Disclosure

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-0335

Affected Products

Cisco Prime Collaboration Provisioning