CVE-2018-0335
Description
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view sensitive data. The vulnerability is due to improper logging of authentication data. An attacker could exploit this vulnerability by monitoring a specific World-Readable file for this authentication data (Cleartext Passwords). An exploit could allow the attacker to gain authentication information for other users. Cisco Bug IDs: CSCvd86602.
Risk Information
Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.525
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Cisco Prime Collaboration Provisioning Cleartext Passwords Written to World-Readable File Vulnerability For Cisco Prime Collaboration | NCM |
| Insertion of Sensitive Information into Log File Vulnerability (CVE-2018-0335) | NCM |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-1705997 | Security Update for Cisco Prime Collaboration 11.0(0.815) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234