CVE-2018-0319
published 2018-06-07CVE-2018-0319: A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gain…
PriorityP268critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.16%
86.5th percentile
A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient validation of a password recovery request. An attacker could exploit this vulnerability by submitting a password recovery request and changing the password for any user on an affected system. An exploit could allow the attacker to gain administrative-level privileges on the affected system. This vulnerability affects Cisco Prime Collaboration Provisioning (PCP) Releases 11.6 and prior. Cisco Bug IDs: CSCvd07253.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | prime_collaboration | <= 12.1 | — |
| cisco | prime_collaboration_provisioning | <= 11.6 | — |
| cisco | prime_collaboration_provisioning_unauthorized_password_recovery | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target the password recovery function of Cisco Prime Collaboration Provisioning (PCP); look for unauthenticated password recovery requests that result in password changes for arbitrary users, including administrative accounts. ↗
- →Monitor for unauthenticated access attempts targeting the PCP password recovery endpoint, particularly from external/remote sources with no prior session context. ↗
- →Alert on privilege escalation indicators following a password recovery event on PCP — successful exploitation grants administrative-level privileges. ↗
- ·Affected versions are Cisco Prime Collaboration Provisioning (PCP) Releases 11.6 and prior; ensure detection scope covers all such deployments. ↗
- ·There are no workarounds available; detection and patching are the only mitigations. Prioritize alerting on exploitation attempts until patched. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Prime Collaboration Provisioning Unauthorized Password Recovery Vulnerability
vendor_cisco·2018-06-06·CVSS 7.5
CVE-2018-0319 [HIGH] CWE-255 Cisco Prime Collaboration Provisioning Unauthorized Password Recovery Vulnerability
Cisco Prime Collaboration Provisioning Unauthorized Password Recovery Vulnerability
A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device.
The vulnerability is due to insufficient validation of a password recovery request. An attacker could exploit this vulnerability by submitting a password recovery request and changing the password for any user on an affected system. An exploit could allow the attacker to gain administrative-level privileges on the affected system.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https:/
Cisco
Cisco Prime Collaboration Provisioning Unauthorized Password Recovery Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0319 Cisco Prime Collaboration Provisioning Unauthorized Password Recovery Vulnerability
CVE-2018-0319: Cisco Prime Collaboration Provisioning Unauthorized Password Recovery Vulnerability
A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient validation of a password recovery request. An attacker could exploit this vulnerability by submitting a password recovery request and changing the password for any user on an affected system. An exploit could allow the attacker to gain administrative-level privileges on the affected system. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-255, CWE-255
Bug IDs: CSCvd07253
GHSA
GHSA-2x7m-3p63-3m3v: A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to g
ghsa_unreviewed·2022-05-13
CVE-2018-0319 [CRITICAL] CWE-287 GHSA-2x7m-3p63-3m3v: A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to g
A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient validation of a password recovery request. An attacker could exploit this vulnerability by submitting a password recovery request and changing the password for any user on an affected system. An exploit could allow the attacker to gain administrative-level privileges on the affected system. This vulnerability affects Cisco Prime Collaboration Provisioning (PCP) Releases 11.6 and prior. Cisco Bug IDs: CSCvd07253.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-12633 camel-hessian: Apache Camel's Hessian unmarshalling operation is vulnerable to Remote Code Execution attacks
bugzilla·2017-11-15·CVSS 9.8
CVE-2017-12633 [CRITICAL] CVE-2017-12633 camel-hessian: Apache Camel's Hessian unmarshalling operation is vulnerable to Remote Code Execution attacks
CVE-2017-12633 camel-hessian: Apache Camel's Hessian unmarshalling operation is vulnerable to Remote Code Execution attacks
Apache Camel's camel-hessian component is vulnerable to Java object
de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
Versions Affected: Camel 2.19.0 to 2.19.3 and Camel 2.20.0
The unsupported Camel 2.x (2.18 and earlier) versions may be also affected.
References:
https://camel.apache.org/security-advisories.data/CVE-2017-12633.txt.asc
https://issues.apache.org/jira/browse/CAMEL-11923
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Fuse
Via RHSA-2018:0319 https://access.redhat.com/errata/RHSA-2018:0319
---
This vulnerability is out of security support scope for the following product:
Bugzilla
CVE-2017-2617 Hawtio: Unrestricted file upload leads to RCE
bugzilla·2017-02-05·CVSS 7.6
CVE-2017-2617 [HIGH] CVE-2017-2617 Hawtio: Unrestricted file upload leads to RCE
CVE-2017-2617 Hawtio: Unrestricted file upload leads to RCE
It was found that a flaw in hawtio could cause remote code execution via file upload. An attacker could use this vulnerability to upload crafted file which could be executed on target machine where hawtio is deployed.
Discussion:
Acknowledgments:
Name: Hooman Broujerdi (Red Hat)
---
This issue has been addressed in the following products:
Red Hat JBoss Fuse
Via RHSA-2018:0319 https://access.redhat.com/errata/RHSA-2018:0319
---
This vulnerability is out of security support scope for the following products:
* Red Hat JBoss Fuse 6
* Red Hat JBoss A-MQ 6
Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.
http://www.securityfocus.com/bid/104431http://www.securitytracker.com/id/1041079https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-prime-password-recoveryhttp://www.securityfocus.com/bid/104431http://www.securitytracker.com/id/1041079https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-prime-password-recovery
2018-06-07
Published