Cisco Prime Collaboration Provisioning vulnerabilities
11 known vulnerabilities affecting cisco/cisco_prime_collaboration_provisioning.
Total CVEs
11
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH3MEDIUM6
Vulnerabilities
Page 1 of 1
CVE-2021-34732MEDIUMCVSS 6.1vn/a2021-09-02
CVE-2021-34732 [MEDIUM] CWE-79 CVE-2021-34732: A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning coul
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker c
cvelistv5nvd
CVE-2020-3184HIGHCVSS 7.2vn/a2020-05-22
CVE-2020-3184 [HIGH] CWE-89 CVE-2020-3184: A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning Soft
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface improperly validates user input for specific SQL queries. An attacker could explo
cvelistv5nvd
CVE-2020-3193MEDIUMCVSS 5.3≥ unspecified, < n/a2020-03-04
CVE-2020-3193 [MEDIUM] CWE-200 CVE-2020-3193: A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning coul
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to obtain sensitive information about an affected device. The vulnerability exists because replies from the web-based management interface include unnecessary server information. An attacker could exploit this
cvelistv5nvd
CVE-2020-3192MEDIUMCVSS 6.1≥ unspecified, < n/a2020-03-04
CVE-2020-3192 [MEDIUM] CWE-79 CVE-2020-3192: A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning coul
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interf
cvelistv5nvd
CVE-2018-15389CRITICALCVSS 9.8vn/a2018-10-05
CVE-2018-15389 [CRITICAL] CWE-255 CVE-2018-15389: A vulnerability in the install function of Cisco Prime Collaboration Provisioning (PCP) could allow
A vulnerability in the install function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the administrative web interface using a default hard-coded username and password that are used during install. The vulnerability is due to a hard-coded password that, in some cases, is not replaced with
cvelistv5nvd
CVE-2018-0141HIGHCVSS 8.4vCisco Prime Collaboration Provisioning2018-03-08
CVE-2018-0141 [HIGH] CWE-798 CVE-2018-0141: A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software 11
A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software 11.6 could allow an unauthenticated, local attacker to log in to the underlying Linux operating system. The vulnerability is due to a hard-coded account password on the system. An attacker could exploit this vulnerability by connecting to the affected system via Secure Shell (SSH) using the hard-coded cred
cvelistv5
CVE-2017-12276HIGHCVSS 8.1vCisco Prime Collaboration Provisioning2017-11-02
CVE-2017-12276 [HIGH] CWE-20 CVE-2017-12276: A vulnerability in the web framework code for the SQL database interface of the Cisco Prime Collaboration Provisioning application could allow an auth
A vulnerability in the web framework code for the SQL database interface of the Cisco Prime Collaboration Provisioning application could allow an authenticated, remote attacker to impact the confidentiality and integrity of the application by executing arbitrary SQL queries, aka SQL Injection. The attac
cvelistv5
CVE-2017-6636MEDIUMCVSS 6.5vCisco Prime Collaboration Provisioning2017-05-22
CVE-2017-6636 [MEDIUM] CWE-22 CVE-2017-6636: A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker to view any file on an affected system. The vulnerability exists because the affected software does not perform proper input validation of HTTP requests and fails to apply role-based acces
cvelistv5
CVE-2017-6637MEDIUMCVSS 6.5vCisco Prime Collaboration Provisioning2017-05-22
CVE-2017-6637 [MEDIUM] CWE-264 CVE-2017-6637: A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker to delete any file from an affected system. The vulnerability exists because the affected software does not perform proper input validation of HTTP requests and fails to apply role-based
cvelistv5
CVE-2017-6635MEDIUMCVSS 6.5vCisco Prime Collaboration Provisioning2017-05-22
CVE-2017-6635 [MEDIUM] CWE-264 CVE-2017-6635: A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 12
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 12.1) could allow an authenticated, remote attacker to delete any file from an affected system. The vulnerability exists because the affected software does not perform proper input validation of HTTP requests and fails to apply role-based
cvelistv5
CVE-2017-6622CRITICALCVSS 9.8PoCvCisco Prime Collaboration Provisioning2017-05-18
CVE-2017-6622 [CRITICAL] CWE-264 CVE-2017-6622: A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authenticati
A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges. The vulnerability is due to missing security constraints in certain HTTP request methods, which
cvelistv5