CVE-2020-3193
published 2020-03-04CVE-2020-3193: A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to obtain…
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
1.11%
62.1th percentile
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to obtain sensitive information about an affected device. The vulnerability exists because replies from the web-based management interface include unnecessary server information. An attacker could exploit this vulnerability by inspecting replies received from the web-based management interface. A successful exploit could allow the attacker to obtain details about the operating system, including the web server version that is running on the device, which could be used to perform further attacks.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_prime_collaboration_provisioning | >= unspecified < n/a | n/a |
| cisco | prime_collaboration_provisioning | < 12.6 | 12.6 |
| cisco | prime_collaboration_provisioning | — | — |
| cisco | prime_collaboration_provisioning | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q8mr-vcxq-vpqm: A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to obt
ghsa_unreviewed·2022-05-24
CVE-2020-3193 [MEDIUM] GHSA-q8mr-vcxq-vpqm: A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to obt
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to obtain sensitive information about an affected device. The vulnerability exists because replies from the web-based management interface include unnecessary server information. An attacker could exploit this vulnerability by inspecting replies received from the web-based management interface. A successful exploit could allow the attacker to obtain details about the operating system, including the web server version that is running on the device, which could be used to perform further attacks.
Cisco
Cisco Prime Collaboration Provisioning Information Disclosure Vulnerability
vendor_cisco·2020-03-04·CVSS 5.3
CVE-2020-3193 [MEDIUM] CWE-200 Cisco Prime Collaboration Provisioning Information Disclosure Vulnerability
Cisco Prime Collaboration Provisioning Information Disclosure Vulnerability
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to obtain sensitive information about an affected device.
The vulnerability exists because replies from the web-based management interface include unnecessary server information. An attacker could exploit this vulnerability by inspecting replies received from the web-based management interface. A successful exploit could allow the attacker to obtain details about the operating system, including the web server version that is running on the device, which could be used to perform further attacks.
There are no workarounds that address this vulnerability.
This advisory is ava
Cisco
Cisco Prime Collaboration Provisioning Information Disclosure Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3193 Cisco Prime Collaboration Provisioning Information Disclosure Vulnerability
CVE-2020-3193: Cisco Prime Collaboration Provisioning Information Disclosure Vulnerability
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to obtain sensitive information about an affected device. The vulnerability exists because replies from the web-based management interface include unnecessary server information. An attacker could exploit this vulnerability by inspecting replies received from the web-based management interface. A successful exploit could allow the attacker to obtain
CVSS: 3.0
CWE: CWE-200, CWE-200
Bug IDs: CSCvs29764
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-03-04
Published