Cisco Prime Collaboration Assurance vulnerabilities

20 known vulnerabilities affecting cisco/prime_collaboration_assurance.

Total CVEs
20
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH5MEDIUM11

Vulnerabilities

Page 1 of 1
CVE-2019-1856MEDIUMCVSS 6.1v12.12019-05-03
CVE-2019-1856 [MEDIUM] CWE-79 CVE-2019-1856: A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance (PCA) c A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance (PCA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to the insufficient validation of data supplied by external
nvd
CVE-2019-1662CRITICALCVSS 9.1fixed in 12.1v12.12019-02-21
CVE-2019-1662 [HIGH] CWE-287 CVE-2019-1662: A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assura A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated, remote attacker to access the system as a valid user. The vulnerability is due to insufficient authentication controls. An attacker could exploit this vulnerability by connecting to the QOVR service with
nvd
CVE-2018-15438MEDIUMCVSS 6.5v12.12018-10-17
CVE-2018-15438 [MEDIUM] CWE-352 CVE-2018-15438: A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could a A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the
nvd
CVE-2018-0458MEDIUMCVSS 6.1v11.6.02018-10-05
CVE-2018-0458 [MEDIUM] CWE-79 CVE-2018-0458: A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could a A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-base
nvd
CVE-2018-0321CRITICALCVSS 9.8≤ 11.62018-06-07
CVE-2018-0321 [CRITICAL] CWE-287 CVE-2018-0321: A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remo A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invocation (RMI) system. The vulnerability is due to an open port in the Network Interface and Configuration Engine (NICE) service. An attacker could exploit this vulnerability by accessing the open RMI sys
nvd
CVE-2017-6779HIGHCVSS 7.5≥ 11.6, < 11.6_es16≥ 12.1, < 12.1_es22018-06-07
CVE-2017-6779 [HIGH] CWE-399 CVE-2017-6779: Multiple Cisco products are affected by a vulnerability in local file management for certain system Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because a certain system log file does not have a maxi
nvd
CVE-2018-0141HIGHCVSS 8.4v11.62018-03-08
CVE-2018-0141 [HIGH] CWE-798 CVE-2018-0141: A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software 11.6 could allow an unauthe A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software 11.6 could allow an unauthenticated, local attacker to log in to the underlying Linux operating system. The vulnerability is due to a hard-coded account password on the system. An attacker could exploit this vulnerability by connecting to the affected system via Secure Shell (SSH)
nvd
CVE-2017-6659HIGHCVSS 8.8v11.5\(0\)v11.62017-06-13
CVE-2017-6659 [HIGH] CWE-352 CVE-2017-6659: A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could a A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. More Information: CSCvc91800. Known Affected Releases: 11.5(0) 11.6.
nvd
CVE-2017-3844MEDIUMCVSS 4.3v11.0.0v11.1.0+1 more2017-02-22
CVE-2017-3844 [MEDIUM] CWE-20 CVE-2017-3844: A vulnerability in exporting functions of the user interface for Cisco Prime Collaboration Assurance A vulnerability in exporting functions of the user interface for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to view file directory listings and download files. Affected Products: Cisco Prime Collaboration Assurance software versions 11.0, 11.1, and 11.5 are vulnerable. Cisco Prime Collaboration Assurance software
nvd
CVE-2017-3845MEDIUMCVSS 6.1v11.0.0v11.1.0+1 more2017-02-22
CVE-2017-3845 [MEDIUM] CWE-79 CVE-2017-3845: A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could a A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. Affected Products: Cisco Prime Collaboration Assurance software versions 11.0, 11.1, and 1
nvd
CVE-2017-3843MEDIUMCVSS 4.3v11.0.0v11.1.0+1 more2017-02-22
CVE-2017-3843 [MEDIUM] CWE-20 CVE-2017-3843: A vulnerability in the file download functions for Cisco Prime Collaboration Assurance could allow a A vulnerability in the file download functions for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to download system files that should be restricted. More Information: CSCvc99446. Known Affected Releases: 11.5(0).
nvd
CVE-2016-9200MEDIUMCVSS 6.1v10.5.1v10.6.02016-12-14
CVE-2016-9200 [MEDIUM] CWE-79 CVE-2016-9200: A vulnerability in the web framework code of Cisco Prime Collaboration Assurance could allow an unau A vulnerability in the web framework code of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface. More Information: CSCut43268. Known Affected Releases: 10.5(1) 10.6.
nvd
CVE-2016-1392HIGHCVSS 7.4v10.5.0v10.5.1+2 more2016-05-05
CVE-2016-1392 [HIGH] CVE-2016-1392: Open redirect vulnerability in Cisco Prime Collaboration Assurance Software 10.5 through 11.0 allows Open redirect vulnerability in Cisco Prime Collaboration Assurance Software 10.5 through 11.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCuu34121.
nvd
CVE-2015-6389CRITICALCVSS 9.0v10.5.1v10.6.02015-12-13
CVE-2015-6389 [CRITICAL] CWE-287 CVE-2015-6389: Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote attackers to obtain access by establishing an SSH session and leveraging knowledge of this account's password, aka Bug ID CSCus62707.
nvd
CVE-2015-6330MEDIUMCVSS 6.8v10.5.1v10.6.02015-11-18
CVE-2015-6330 [MEDIUM] CWE-352 CVE-2015-6330: Cross-site request forgery (CSRF) vulnerability in Cisco Prime Collaboration Assurance 10.5(1) and 1 Cross-site request forgery (CSRF) vulnerability in Cisco Prime Collaboration Assurance 10.5(1) and 10.6 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCus62712.
nvd
CVE-2015-6328MEDIUMCVSS 6.8v10.5.12015-10-13
CVE-2015-6328 [MEDIUM] CWE-200 CVE-2015-6328: The web framework in Cisco Prime Collaboration Assurance (PCA) 10.5(1) allows remote authenticated u The web framework in Cisco Prime Collaboration Assurance (PCA) 10.5(1) allows remote authenticated users to bypass intended access restrictions and read arbitrary files via a crafted URL, aka Bug ID CSCus88380.
nvd
CVE-2015-6331MEDIUMCVSS 6.5v10.5.12015-10-12
CVE-2015-6331 [MEDIUM] CWE-89 CVE-2015-6331: SQL injection vulnerability in the web framework in Cisco Prime Collaboration Assurance 10.5(1) allo SQL injection vulnerability in the web framework in Cisco Prime Collaboration Assurance 10.5(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCus39887.
nvd
CVE-2015-4304CRITICALCVSS 9.0v9.0.0v9.5.0+4 more2015-09-20
CVE-2015-4304 [CRITICAL] CWE-264 CVE-2015-4304: The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authent The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended access restrictions, and create administrative accounts or read data from arbitrary tenant domains, via a crafted URL, aka Bug IDs CSCus62671 and CSCus62652.
nvd
CVE-2015-4306HIGHCVSS 8.5v9.0.0v9.5.0+4 more2015-09-20
CVE-2015-4306 [HIGH] CWE-264 CVE-2015-4306: The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authent The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended login-session read restrictions, and impersonate administrators of arbitrary tenant domains, by discovering a session identifier and constructing a crafted URL, aka Bug IDs CSCus88343 and CSCus88334.
nvd
CVE-2015-4305MEDIUMCVSS 4.0v9.0.0v9.5.0+4 more2015-09-20
CVE-2015-4305 [MEDIUM] CWE-264 CVE-2015-4305: The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authent The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended system-database read restrictions, and discover credentials or SNMP communities for arbitrary tenant domains, via a crafted URL, aka Bug ID CSCus62656.
nvd