CVE-2019-1662
published 2019-02-21CVE-2019-1662: A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated, remote…
PriorityP260critical9.1CVSS 3.0
AVNACLPRNUINSUCHIHAN
EPSS
1.78%
75.8th percentile
A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated, remote attacker to access the system as a valid user. The vulnerability is due to insufficient authentication controls. An attacker could exploit this vulnerability by connecting to the QOVR service with a valid username. A successful exploit could allow the attacker to perform actions with the privileges of the user that is used for access. This vulnerability affects Cisco PCA Software Releases prior to 12.1 SP2.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_prime_collaboration_assurance | — | — |
| cisco | prime_collaboration_assurance | < 12.1 | 12.1 |
| cisco | prime_collaboration_assurance | — | — |
| cisco | prime_collaboration_assurance | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector: unauthenticated attacker connects to the QOVR (Quality of Voice Reporting) service supplying only a valid username — no password required. Monitor for unexpected or unauthenticated connections to the QOVR service. ↗
- →Scope: Cisco Prime Collaboration Assurance (PCA) Software releases prior to 12.1 SP2 are affected. Identify and flag any such instances exposed to untrusted networks. ↗
- →CWE-287 (Improper Authentication) — detection should focus on authentication bypass patterns on the QOVR service endpoint, such as sessions established without a corresponding credential-validation event. ↗
- ·No workarounds are available for this vulnerability; patching to 12.1 SP2 or later is the only remediation. Ensure network-level controls restrict access to the QOVR service from untrusted sources as a compensating control. ↗
- ·Cisco internal bug ID CSCvj07241 tracks this issue; use this identifier when cross-referencing vendor advisories or patch notes. ↗
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_cisco8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Prime Collaboration Assurance Software Unauthenticated Access Vulnerability
vendor_cisco·2019-02-20·CVSS 8.2
CVE-2019-1662 [HIGH] CWE-287 Cisco Prime Collaboration Assurance Software Unauthenticated Access Vulnerability
Cisco Prime Collaboration Assurance Software Unauthenticated Access Vulnerability
A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated, remote attacker to access the system as a valid user.
The vulnerability is due to insufficient authentication controls. An attacker could exploit this vulnerability by connecting to the QOVR service with a valid username. A successful exploit could allow the attacker to perform actions with the privileges of the user that is used for access.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/cent
Cisco
Cisco Prime Collaboration Assurance Software Unauthenticated Access Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1662 Cisco Prime Collaboration Assurance Software Unauthenticated Access Vulnerability
CVE-2019-1662: Cisco Prime Collaboration Assurance Software Unauthenticated Access Vulnerability
A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated, remote attacker to access the system as a valid user. The vulnerability is due to insufficient authentication controls. An attacker could exploit this vulnerability by connecting to the QOVR service with a valid username. A successful exploit could allow the attacker to perform actions with the privileges of the user that is used for access. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-287, CWE-287
Bug IDs: CSCvj07241
GHSA
GHSA-jcx4-2jj5-xr9c: A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated,
ghsa_unreviewed·2022-05-13
CVE-2019-1662 [CRITICAL] CWE-287 GHSA-jcx4-2jj5-xr9c: A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated,
A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated, remote attacker to access the system as a valid user. The vulnerability is due to insufficient authentication controls. An attacker could exploit this vulnerability by connecting to the QOVR service with a valid username. A successful exploit could allow the attacker to perform actions with the privileges of the user that is used for access. This vulnerability affects Cisco PCA Software Releases prior to 12.1 SP2.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-02-21
Published