First published: Wed Nov 07 2018(Updated: )
A vulnerability in the web-based UI of Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to overwrite files on the file system. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by using a specific UI input field to provide a custom path location. A successful exploit could allow the attacker to overwrite files on the file system.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Collaboration | =12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15450 is a vulnerability in the web-based UI of Cisco Prime Collaboration Assurance that could allow an authenticated, remote attacker to overwrite files on the file system.
CVE-2018-15450 has a severity score of 6.5 (medium).
The affected software for CVE-2018-15450 is Cisco Prime Collaboration Assurance version 12.1.
An attacker can exploit CVE-2018-15450 by using a specific UI input field to overwrite files on the file system.
More information about CVE-2018-15450 can be found at the following references: [http://www.securityfocus.com/bid/105864](http://www.securityfocus.com/bid/105864) and [https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-pca-overwrite](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-pca-overwrite).