First published: Thu Jun 07 2018(Updated: )
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view sensitive data. The vulnerability is due to improper logging of authentication data. An attacker could exploit this vulnerability by monitoring a specific World-Readable file for this authentication data (Cleartext Passwords). An exploit could allow the attacker to gain authentication information for other users. Cisco Bug IDs: CSCvd86602.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Collaboration | =12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this Cisco Prime Collaboration Provisioning vulnerability is CVE-2018-0335.
The severity of CVE-2018-0335 is high with a CVSS score of 7.8.
The affected software of CVE-2018-0335 is Cisco Prime Collaboration Provisioning version 12.2.
The vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view sensitive data due to improper logging of authentication data.
An attacker can exploit CVE-2018-0335 by monitoring the web portal authentication process of Cisco Prime Collaboration Provisioning.
Yes, here are some references for CVE-2018-0335 vulnerability: [SecurityFocus](http://www.securityfocus.com/bid/104473), [SecurityTracker](http://www.securitytracker.com/id/1041069), [Cisco Security Advisory](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-cpcp-id)