cbcvebase.

Cisco Prime Collaboration Provisioning vulnerabilities

5 known vulnerabilities affecting cisco/cisco_prime_collaboration_provisioning.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2018-15389P2CRITICALCVSS 9.8vn/a2018-10-05
CVE-2018-15389 [CRITICAL] CWE-255 CVE-2018-15389: A vulnerability in the install function of Cisco Prime Collaboration Provisioning (PCP) could allow A vulnerability in the install function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the administrative web interface using a default hard-coded username and password that are used during install. The vulnerability is due to a hard-coded password that, in some cases, is not replaced with
nvd
CVE-2020-3184P3HIGHCVSS 7.2vn/a2020-05-22
CVE-2020-3184 [HIGH] CWE-89 CVE-2020-3184: A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning Soft A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface improperly validates user input for specific SQL queries. An attacker could explo
nvd
CVE-2021-34732P4MEDIUMCVSS 6.1vn/a2021-09-02
CVE-2021-34732 [MEDIUM] CWE-79 CVE-2021-34732: A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning coul A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker c
nvd
CVE-2020-3192P4MEDIUMCVSS 6.1≥ unspecified, < n/a2020-03-04
CVE-2020-3192 [MEDIUM] CWE-79 CVE-2020-3192: A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning coul A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interf
nvd
CVE-2020-3193P4MEDIUMCVSS 5.3≥ unspecified, < n/a2020-03-04
CVE-2020-3193 [MEDIUM] CWE-200 CVE-2020-3193: A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning coul A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to obtain sensitive information about an affected device. The vulnerability exists because replies from the web-based management interface include unnecessary server information. An attacker could exploit this
nvd
Cisco Prime Collaboration Provisioning vulnerabilities | cvebase