Cisco Prime Collaboration Provisioning vulnerabilities
32 known vulnerabilities affecting cisco/prime_collaboration_provisioning.
Total CVEs
32
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH9MEDIUM16
Vulnerabilities
Page 2 of 2
CVE-2017-6704P3MEDIUMCVSS 6.5v12.12017-07-04
CVE-2017-6704 [MEDIUM] CWE-22 CVE-2017-6704: A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allo
A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allow an authenticated, remote attacker to perform arbitrary file downloads that could allow the attacker to read files from the underlying filesystem. More Information: CSCvc90335. Known Affected Releases: 12.1.
nvd
CVE-2015-6329P3MEDIUMCVSS 6.5v10.6.0v11.0.02015-10-12
CVE-2015-6329 [MEDIUM] CWE-89 CVE-2015-6329: SQL injection vulnerability in Cisco Prime Collaboration Provisioning 10.6 and 11.0 allows remote au
SQL injection vulnerability in Cisco Prime Collaboration Provisioning 10.6 and 11.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCut64074.
nvd
CVE-2018-0391P3MEDIUMCVSS 6.5≤ 12.22018-08-01
CVE-2018-0391 [MEDIUM] CWE-285 CVE-2018-0391: A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allo
A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to cause the system to become inoperable. The vulnerability is due to insufficient validation of a password change request. An attacker could exploit this vulnerability by changing a specific administrator account pas
nvd
CVE-2017-6703P4MEDIUMCVSS 5.9v11.2_basev11.5.0+2 more2017-07-04
CVE-2017-6703 [MEDIUM] CWE-287 CVE-2017-6703: A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allo
A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, remote attacker to hijack another user's session. More Information: CSCvc90346. Known Affected Releases: 12.1.
nvd
CVE-2018-0205P4MEDIUMCVSS 6.1v12.12018-02-22
CVE-2018-0205 [MEDIUM] CWE-79 CVE-2018-0205: A vulnerability in the User Provisioning tab in the Cisco Prime Collaboration Provisioning Tool coul
A vulnerability in the User Provisioning tab in the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. The vulnerability is due to improper input validation. An attacker could exploit this vulnerability by placing a malicious string in the Prime Collaboration Provi
nvd
CVE-2017-6755P4MEDIUMCVSS 6.1v12.12017-07-25
CVE-2017-6755 [MEDIUM] CWE-79 CVE-2017-6755: A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning (PCP) Tool could all
A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning (PCP) Tool could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCvc90312. Known Affected Releases: 12.1.
nvd
CVE-2021-34732P4MEDIUMCVSS 6.1≤ 12.6_su3\(1\)2021-09-02
CVE-2021-34732 [MEDIUM] CWE-79 CVE-2021-34732: A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning coul
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker c
nvd
CVE-2016-6451P4MEDIUMCVSS 6.1v10.6.02016-11-03
CVE-2016-6451 [MEDIUM] CWE-79 CVE-2016-6451: Multiple vulnerabilities in the web framework code of the Cisco Prime Collaboration Provisioning cou
Multiple vulnerabilities in the web framework code of the Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCut43061 CSCut43066 CSCut43736 CSCut43738 CSCut43741 CSCut43745 CSCut43748 CSCut
nvd
CVE-2020-3192P4MEDIUMCVSS 6.1fixed in 12.6v12.62020-03-04
CVE-2020-3192 [MEDIUM] CWE-79 CVE-2020-3192: A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning coul
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interf
nvd
CVE-2020-3193P4MEDIUMCVSS 5.3fixed in 12.6v12.62020-03-04
CVE-2020-3193 [MEDIUM] CWE-200 CVE-2020-3193: A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning coul
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to obtain sensitive information about an affected device. The vulnerability exists because replies from the web-based management interface include unnecessary server information. An attacker could exploit this
nvd
CVE-2017-6705P4MEDIUMCVSS 5.5v12.12017-07-04
CVE-2017-6705 [MEDIUM] CWE-200 CVE-2017-6705: A vulnerability in the filesystem of the Cisco Prime Collaboration Provisioning tool could allow an
A vulnerability in the filesystem of the Cisco Prime Collaboration Provisioning tool could allow an authenticated, local attacker to acquire sensitive information. More Information: CSCvc82973. Known Affected Releases: 12.1.
nvd
CVE-2017-6706P4MEDIUMCVSS 5.1v11.2_basev11.5.0+2 more2017-07-04
CVE-2017-6706 [MEDIUM] CWE-200 CVE-2017-6706: A vulnerability in the logging subsystem of the Cisco Prime Collaboration Provisioning tool could al
A vulnerability in the logging subsystem of the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, local attacker to acquire sensitive information. More Information: CSCvd07260. Known Affected Releases: 12.1.
nvd
← Previous2 / 2