CVE-2017-6622
A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and...
- Published
- May 18, 2017
- Updated
- Aug 5, 2024
- Assigning CNA
- cisco
- Evidence observed
- Sep 27, 2017
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:CHigh · next 30 days
- Percentile
- 98.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges. The vulnerability is due to missing security constraints in certain HTTP request methods, which could allow access to files via the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the targeted application. This vulnerability affects Cisco Prime Collaboration Provisioning Software Releases prior to 12.1. Cisco Bug IDs: CSCvc98724.
Sources
1- Cisco Prime Collaboration Provisioning < 12.1 - Authentication Bypass / Remote Code ExecutionExploit
Adam Brown · hardware · Sep 27, 2017
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.