cbcvebase.
CVE-2018-0321
published 2018-06-07

CVE-2018-0321: A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invocation…

PriorityP266critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.62%
88.2th percentile
A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invocation (RMI) system. The vulnerability is due to an open port in the Network Interface and Configuration Engine (NICE) service. An attacker could exploit this vulnerability by accessing the open RMI system on an affected PCP instance. An exploit could allow the attacker to perform malicious actions that affect PCP and the devices that are connected to it. This vulnerability affects Cisco Prime Collaboration Provisioning (PCP) Releases 11.6 and prior. Cisco Bug IDs: CSCvd61746.

Affected

4 ranges
VendorProductVersion rangeFixed in
ciscoprime_collaboration<= 11.6
ciscoprime_collaboration_assurance<= 11.6
ciscoprime_collaboration_provisioning<= 11.6
ciscoprime_collaboration_provisioning_unauthenticated

Detection & IOCsextracted from sources · hover to see the quote

portRMI open port (NICE service)
  • Monitor for unauthenticated inbound connections to the Java RMI port exposed by the NICE service on Cisco Prime Collaboration Provisioning instances.
  • Alert on any external/unauthenticated access attempts to the Java RMI service on PCP hosts, particularly from untrusted network segments.
  • ·Affected versions are Cisco Prime Collaboration Provisioning (PCP) Release 11.6 and prior; upgrade to a patched release.
  • ·No workarounds are available; the only remediation is applying the vendor-supplied software update.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.