cisco-sa-20181003-cpcp-password: Cisco Prime Collaboration Provisioning Intermittent Hard-Coded Password Vulnerability
A vulnerability in the install function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the administrative web interface using a default hard-coded username and password that are used during install.
The vulnerability is due to a hard-coded password that, in some cases, is not replaced with a unique password. A successful exploit could allow the attacker to access the administrative web interface with administrator-level privileges. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181003-cpcp-password
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20181003-cpcp-password?
The severity of the vulnerability cisco-sa-20181003-cpcp-password is considered critical due to the potential for unauthorized access.
How do I fix cisco-sa-20181003-cpcp-password?
To fix cisco-sa-20181003-cpcp-password, replace the default hard-coded username and password with strong, unique credentials.
Who is affected by cisco-sa-20181003-cpcp-password?
Anyone using Cisco Prime Collaboration Provisioning is affected by cisco-sa-20181003-cpcp-password.
Can cisco-sa-20181003-cpcp-password be exploited remotely?
Yes, cisco-sa-20181003-cpcp-password can be exploited remotely by an unauthenticated attacker.
What is the nature of the vulnerability in cisco-sa-20181003-cpcp-password?
The vulnerability in cisco-sa-20181003-cpcp-password allows access to the administrative web interface due to default hard-coded credentials.