Local Authentication Bypass in Cisco Prime Collaboration Provisioning Software
CVE-2018-0141
8.4HIGH
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 8 March 2018
Summary
A vulnerability in Cisco Prime Collaboration Provisioning Software 11.6 allows unauthenticated local attackers to log into the underlying Linux operating system due to the existence of a hard-coded account password. Attackers can exploit this flaw by connecting via Secure Shell (SSH) using these credentials. Once access is gained as a low-privileged user, the attacker may further escalate privileges to root, potentially taking complete control of the affected device.
Affected Version(s)
Cisco Prime Collaboration Provisioning Cisco Prime Collaboration Provisioning
References
CVSS V3.1
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved