CVE-2018-0322
Last modified
CVE-2018-0322 is a vulnerability of currently unknown severity. A vulnerability in the web management interface of Cisco Prime Collaboration Provisioning (PCP) could allow an authenticated, remote attacker to modify sensitive data that is associated with arbitrary accounts on an affected device. The vulnerability is due to a failure to enforce access restrictions on the Help Desk and User Provisioning roles that are assigned to authenticated users. EPSS estimates a 2.63% chance of exploitation in the next 30 days.
Description
A vulnerability in the web management interface of Cisco Prime Collaboration Provisioning (PCP) could allow an authenticated, remote attacker to modify sensitive data that is associated with arbitrary accounts on an affected device. The vulnerability is due to a failure to enforce access restrictions on the Help Desk and User Provisioning roles that are assigned to authenticated users. This failure could allow an authenticated attacker to modify critical attributes of higher-privileged accounts on the device. A successful exploit could allow the attacker to gain elevated privileges on the device. This vulnerability affects Cisco Prime Collaboration Provisioning (PCP) Releases 12.1 and prior. Cisco Bug IDs: CSCvd61779.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Prime Collaboration | <= 12.1 |
| Cisco | Prime Collaboration Provisioning | <= 12.1 |
References
- http://www.securityfocus.com/bid/104443Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041064Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/104443Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041064Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-0322?
How severe is CVE-2018-0322?
How do I fix CVE-2018-0322?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-0316A vulnerability in the Session Initiation Protocol (SIP) cal…
- CVE-2018-0317A vulnerability in the web interface of Cisco Prime Collabor…
- CVE-2018-0318A vulnerability in the password reset function of Cisco Prim…
- CVE-2018-0319A vulnerability in the password recovery function of Cisco P…
- CVE-2018-0320A vulnerability in the web framework code of Cisco Prime Col…
- CVE-2018-0321A vulnerability in Cisco Prime Collaboration Provisioning (P…
- CVE-2018-0323A vulnerability in the web management interface of Cisco Ent…
- CVE-2018-0324A vulnerability in the CLI of Cisco Enterprise NFV Infrastru…6.7
- CVE-2018-0325A vulnerability in the Session Initiation Protocol (SIP) cal…
- CVE-2018-0326A vulnerability in the web UI of Cisco TelePresence Server S…
- CVE-2018-0327A vulnerability in the web framework of Cisco Identity Servi…
- CVE-2018-0328A vulnerability in the web framework of Cisco Unified Commun…
Are you affected by CVE-2018-0322?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
