cisco-sa-20180606-prime-password-reset: Cisco Prime Collaboration Provisioning Unauthorized Password Reset Vulnerability
A vulnerability in the password reset function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient validation of a password reset request. An attacker could exploit this vulnerability by submitting a password reset request and changing the password for any user on an affected system. An exploit could allow the attacker to gain administrative-level privileges on the affected system.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-prime-password-reset
Affected Software
Event History
Frequently Asked Questions
What is the severity of Cisco-SA-20180606-Prime-Password-Reset?
The severity of Cisco-SA-20180606-Prime-Password-Reset is categorized as high due to the potential for unauthorized access to affected devices.
How do I fix Cisco-SA-20180606-Prime-Password-Reset?
To fix Cisco-SA-20180606-Prime-Password-Reset, update Cisco Prime Collaboration Provisioning to the latest patched version provided by Cisco.
Who is affected by Cisco-SA-20180606-Prime-Password-Reset?
Users of Cisco Prime Collaboration Provisioning are affected by Cisco-SA-20180606-Prime-Password-Reset.
What type of attack does Cisco-SA-20180606-Prime-Password-Reset enable?
Cisco-SA-20180606-Prime-Password-Reset enables unauthenticated remote attackers to gain unauthorized access through the password reset function.
Is there a workaround for Cisco-SA-20180606-Prime-Password-Reset?
There are no official workarounds for Cisco-SA-20180606-Prime-Password-Reset, and upgrading to a secure version is recommended.