cbcvebase.
CVE-2018-0319
published 2018-06-07

CVE-2018-0319: A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gain…

PriorityP268critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.16%
86.5th percentile
A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient validation of a password recovery request. An attacker could exploit this vulnerability by submitting a password recovery request and changing the password for any user on an affected system. An exploit could allow the attacker to gain administrative-level privileges on the affected system. This vulnerability affects Cisco Prime Collaboration Provisioning (PCP) Releases 11.6 and prior. Cisco Bug IDs: CSCvd07253.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscoprime_collaboration<= 12.1
ciscoprime_collaboration_provisioning<= 11.6
ciscoprime_collaboration_provisioning_unauthorized_password_recovery

Detection & IOCsextracted from sources · hover to see the quote

  • Target the password recovery function of Cisco Prime Collaboration Provisioning (PCP); look for unauthenticated password recovery requests that result in password changes for arbitrary users, including administrative accounts.
  • Monitor for unauthenticated access attempts targeting the PCP password recovery endpoint, particularly from external/remote sources with no prior session context.
  • Alert on privilege escalation indicators following a password recovery event on PCP — successful exploitation grants administrative-level privileges.
  • ·Affected versions are Cisco Prime Collaboration Provisioning (PCP) Releases 11.6 and prior; ensure detection scope covers all such deployments.
  • ·There are no workarounds available; detection and patching are the only mitigations. Prioritize alerting on exploitation attempts until patched.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.