CVE-2017-6622
Summary
| CVE | CVE-2017-6622 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-05-18 19:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges. The vulnerability is due to missing security constraints in certain HTTP request methods, which could allow access to files via the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the targeted application. This vulnerability affects Cisco Prime Collaboration Provisioning Software Releases prior to 12.1. Cisco Bug IDs: CSCvc98724. |
Risk And Classification
Primary CVSS: v3.0 9.8 CRITICAL from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-264 | CWE-862 | CWE-264 CWE-264
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 10 | AV:N/AC:L/Au:N/C:C/I:C/A:C |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Prime Collaboration Provisioning | 10.0.0 | All | All | All |
| Application | Cisco | Prime Collaboration Provisioning | 10.5.0 | All | All | All |
| Application | Cisco | Prime Collaboration Provisioning | 10.5.1 | All | All | All |
| Application | Cisco | Prime Collaboration Provisioning | 10.6.0 | All | All | All |
| Application | Cisco | Prime Collaboration Provisioning | 10.6.2 | All | All | All |
| Application | Cisco | Prime Collaboration Provisioning | 11.0.0 | All | All | All |
| Application | Cisco | Prime Collaboration Provisioning | 11.1.0 | All | All | All |
| Application | Cisco | Prime Collaboration Provisioning | 11.5.0 | All | All | All |
| Application | Cisco | Prime Collaboration Provisioning | 9.0.0 | All | All | All |
| Application | Cisco | Prime Collaboration Provisioning | 9.5.0 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | Cisco Prime Collaboration Provisioning | affected Cisco Prime Collaboration Provisioning | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Prime Collaboration Provisioning < 12.1 - Authentication Bypass / Remote Code Execution - Hardware remote Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Cisco Prime Collaboration Provisioning CVE-2017-6622 Authentication Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Cisco Prime Collaboration Provisioning Authentication Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| Cisco Prime Collaboration Provisioning Authentication Bypass Let Remote Users Execute Arbitrary Commands - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.