CVE-2018-0321
published 2018-06-07CVE-2018-0321: A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invocation…
PriorityP266critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.62%
88.2th percentile
A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invocation (RMI) system. The vulnerability is due to an open port in the Network Interface and Configuration Engine (NICE) service. An attacker could exploit this vulnerability by accessing the open RMI system on an affected PCP instance. An exploit could allow the attacker to perform malicious actions that affect PCP and the devices that are connected to it. This vulnerability affects Cisco Prime Collaboration Provisioning (PCP) Releases 11.6 and prior. Cisco Bug IDs: CSCvd61746.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | prime_collaboration | <= 11.6 | — |
| cisco | prime_collaboration_assurance | <= 11.6 | — |
| cisco | prime_collaboration_provisioning | <= 11.6 | — |
| cisco | prime_collaboration_provisioning_unauthenticated | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unauthenticated inbound connections to the Java RMI port exposed by the NICE service on Cisco Prime Collaboration Provisioning instances. ↗
- →Alert on any external/unauthenticated access attempts to the Java RMI service on PCP hosts, particularly from untrusted network segments. ↗
- ·Affected versions are Cisco Prime Collaboration Provisioning (PCP) Release 11.6 and prior; upgrade to a patched release. ↗
- ·No workarounds are available; the only remediation is applying the vendor-supplied software update. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-33wg-wpq3-mx7x: A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invoc
ghsa_unreviewed·2022-05-13
CVE-2018-0321 [CRITICAL] CWE-287 GHSA-33wg-wpq3-mx7x: A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invoc
A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invocation (RMI) system. The vulnerability is due to an open port in the Network Interface and Configuration Engine (NICE) service. An attacker could exploit this vulnerability by accessing the open RMI system on an affected PCP instance. An exploit could allow the attacker to perform malicious actions that affect PCP and the devices that are connected to it. This vulnerability affects Cisco Prime Collaboration Provisioning (PCP) Releases 11.6 and prior. Cisco Bug IDs: CSCvd61746.
Cisco
Cisco Prime Collaboration Provisioning Unauthenticated Remote Method Invocation Vulnerability
vendor_cisco·2018-06-06·CVSS 9.8
CVE-2018-0321 [CRITICAL] CWE-287 Cisco Prime Collaboration Provisioning Unauthenticated Remote Method Invocation Vulnerability
Cisco Prime Collaboration Provisioning Unauthenticated Remote Method Invocation Vulnerability
A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invocation (RMI) system.
The vulnerability is due to an open port in the Network Interface and Configuration Engine (NICE) service. An attacker could exploit this vulnerability by accessing the open RMI system on an affected PCP instance. An exploit could allow the attacker to perform malicious actions that affect PCP and the devices that are connected to it.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps
Cisco
Cisco Prime Collaboration Provisioning Unauthenticated Remote Method Invocation Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0321 Cisco Prime Collaboration Provisioning Unauthenticated Remote Method Invocation Vulnerability
CVE-2018-0321: Cisco Prime Collaboration Provisioning Unauthenticated Remote Method Invocation Vulnerability
A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invocation (RMI) system. The vulnerability is due to an open port in the Network Interface and Configuration Engine (NICE) service. An attacker could exploit this vulnerability by accessing the open RMI system on an affected PCP instance. An exploit could allow the attacker to perform malicious actions that affect PCP and the devices that are connected to it. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-287, CWE-287
Bug IDs: CSCvd61746
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/104409http://www.securitytracker.com/id/1041085https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-prime-rmihttp://www.securityfocus.com/bid/104409http://www.securitytracker.com/id/1041085https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-prime-rmi
2018-06-07
Published