Privilege Escalation in Cisco Prime Collaboration Provisioning
CVE-2018-0336
8.8HIGH
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 7 June 2018
Summary
A flaw in the batch provisioning feature of Cisco Prime Collaboration Provisioning permits an authenticated remote attacker to escalate their privileges to the Administrator level. This vulnerability arises from inadequate authorization checks during batch processing. If exploited, an attacker can upload a crafted batch file, prompting the system to execute it, leading to unauthorized privilege escalation. For further details, refer to Cisco's security advisory and associated Bug IDs.
Affected Version(s)
Cisco Prime Collaboration Provisioning unknown Cisco Prime Collaboration Provisioning unknown
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved