Information disclosure in Cisco Prime Collaboration Provisioning - CVE-2018-0335

 

Information disclosure in Cisco Prime Collaboration Provisioning - CVE-2018-0335

Published: June 7, 2018


Vulnerability identifier: #VU13213
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0335
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local unauthenticated attacker to obtain potentially sensitive information on the target system.

The vulnerability exists in the web portal authentication process of Cisco Prime Collaboration Provisioning due to improper logging of authentication data. A local attacker can monitor a specific file for this authentication data and gain authentication information for other users.


Affected software

Cisco Prime Collaboration Provisioning

How to mitigate CVE-2018-0335

Install update from vendor's website.


External References

Related Security Bulletins