CVE-2018-0335
published 2018-06-07CVE-2018-0335: A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view…
PriorityP342high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.41%
33.3th percentile
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view sensitive data. The vulnerability is due to improper logging of authentication data. An attacker could exploit this vulnerability by monitoring a specific World-Readable file for this authentication data (Cleartext Passwords). An exploit could allow the attacker to gain authentication information for other users. Cisco Bug IDs: CSCvd86602.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | prime_collaboration | — | — |
| cisco | prime_collaboration_provisioning_cleartext_passwords_written_to_world-readable_f | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4gxr-h3cg-2j83: A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to v
ghsa_unreviewed·2022-05-13
CVE-2018-0335 [HIGH] CWE-532 GHSA-4gxr-h3cg-2j83: A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to v
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view sensitive data. The vulnerability is due to improper logging of authentication data. An attacker could exploit this vulnerability by monitoring a specific World-Readable file for this authentication data (Cleartext Passwords). An exploit could allow the attacker to gain authentication information for other users. Cisco Bug IDs: CSCvd86602.
Cisco
Cisco Prime Collaboration Provisioning Cleartext Passwords Written to World-Readable File Vulnerability
vendor_cisco·2018-06-06·CVSS 5.1
CVE-2018-0335 [MEDIUM] CWE-200 Cisco Prime Collaboration Provisioning Cleartext Passwords Written to World-Readable File Vulnerability
Cisco Prime Collaboration Provisioning Cleartext Passwords Written to World-Readable File Vulnerability
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view sensitive data.
The vulnerability is due to improper logging of authentication data. An attacker could exploit this vulnerability by monitoring a specific file for this authentication data. An exploit could allow the attacker to gain authentication information for other users.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-cpcp-id
Cisco
Cisco Prime Collaboration Provisioning Cleartext Passwords Written to World-Readable File Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0335 Cisco Prime Collaboration Provisioning Cleartext Passwords Written to World-Readable File Vulnerability
CVE-2018-0335: Cisco Prime Collaboration Provisioning Cleartext Passwords Written to World-Readable File Vulnerability
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view sensitive data. The vulnerability is due to improper logging of authentication data. An attacker could exploit this vulnerability by monitoring a specific file for this authentication data. An exploit could allow the attacker to gain authentication information for other users. There are no
CVSS: 3.0
CWE: CWE-200, CWE-200
Bug IDs: CSCvd86602
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/104473http://www.securitytracker.com/id/1041069https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-cpcp-idhttp://www.securityfocus.com/bid/104473http://www.securitytracker.com/id/1041069https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-cpcp-id
2018-06-07
Published