CVE-2018-15433
published 2018-10-05CVE-2018-15433: A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information. The…
PriorityP421medium4.3CVSS 3.0
AVNACLPRLUINSUCLINAN
EPSS
1.01%
59.0th percentile
A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker could exploit this vulnerability by sending a GET request to a vulnerable device. A successful exploit could allow the attacker to view sensitive information.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Prime Infrastructure Information Disclosure Vulnerability
vendor_cisco·2018-10-03·CVSS 4.3
CVE-2018-15433 [MEDIUM] CWE-200 Cisco Prime Infrastructure Information Disclosure Vulnerability
Cisco Prime Infrastructure Information Disclosure Vulnerability
A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information.
The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker could exploit this vulnerability by sending a GET request to a vulnerable device. A successful exploit could allow the attacker to view sensitive information.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181003-prime-id
Cisco
Cisco Prime Infrastructure Information Disclosure Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-15433 Cisco Prime Infrastructure Information Disclosure Vulnerability
CVE-2018-15433: Cisco Prime Infrastructure Information Disclosure Vulnerability
A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker could exploit this vulnerability by sending a GET request to a vulnerable device. A successful exploit could allow the attacker to view sensitive information. There are no
CVSS: 3.0
CWE: CWE-200, CWE-200
Bug IDs: CSCvg93152
GHSA
GHSA-x89m-pm5w-mgg4: A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive informatio
ghsa_unreviewed·2022-05-13
CVE-2018-15433 [MEDIUM] CWE-200 GHSA-x89m-pm5w-mgg4: A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive informatio
A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker could exploit this vulnerability by sending a GET request to a vulnerable device. A successful exploit could allow the attacker to view sensitive information.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-10-05
Published