PT-2018-8763 · Cisco · Cisco Prime Collaboration Provisioning
Published
2018-06-07
·
Updated
2019-10-09
·
CVE-2018-0335
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Prime Collaboration Provisioning (affected versions not specified)
Description
A vulnerability in the web portal authentication process could allow an unauthenticated, local attacker to view sensitive data due to improper logging of authentication data. An attacker could exploit this by monitoring a specific world-readable file for authentication data, including cleartext passwords, potentially gaining authentication information for other users.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficiently Protected Credentials
Information Disclosure
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Prime Collaboration Provisioning