SB2019022205 - Authentication bypass in Cisco Prime Collaboration Assurance
Published: February 22, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authentication (CVE-ID: CVE-2019-1662)
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists in the Quality of Voice Reporting (QOVR) service due to insufficient authentication controls. A remote attacker can connect to the QOVR service with a valid username and perform actions with the privileges of the user that is used for access.
Remediation
Install update from vendor's website.