QID 13942

Date Published: 2021-12-06

QID 13942: Cisco Prime Collaboration Provisioning (PCP) Multiple Vulnerabilities (cisco-sa-prime-collab-xss-RjRCe9n7,cisco-sa-prim-collab-disclo-FAnX4DKB)

A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface.
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to obtain sensitive information about an affected device.

Affected Versions:
This vulnerability affects Cisco Prime Collaboration Provisioning (PCP) Releases 12.6 SU1 and prior.

QID Detection Logic(Unauthenticated):
It checks for vulnerable version of Cisco Prime Collaboration Provisioning (PCP) Software by sending a GET request and matching the vulnerable version in response to the query.

A successful exploit could allow the attacker to obtain details about the operating system, including the web server version that is running on the device, which could be used to perform further attacks.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-prime-collab-xss-RjRCe9n7 , cisco-sa-prim-collab-disclo-FAnX4DKBfor more information.

    CVEs related to QID 13942

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-prime-collab-xss-RjRCe9n7 URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-prime-collab-xss-RjRCe9n7