QID 13942
Date Published: 2021-12-06
QID 13942: Cisco Prime Collaboration Provisioning (PCP) Multiple Vulnerabilities (cisco-sa-prime-collab-xss-RjRCe9n7,cisco-sa-prim-collab-disclo-FAnX4DKB)
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface.
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to obtain sensitive information about an affected device.
Affected Versions:
This vulnerability affects Cisco Prime Collaboration Provisioning (PCP) Releases 12.6 SU1 and prior.
QID Detection Logic(Unauthenticated):
It checks for vulnerable version of Cisco Prime Collaboration Provisioning (PCP) Software by sending a GET request and matching the vulnerable version in response to the query.
A successful exploit could allow the attacker to obtain details about the operating system, including the web server version that is running on the device, which could be used to perform further attacks.
Customers are advised to refer to cisco-sa-prime-collab-xss-RjRCe9n7 , cisco-sa-prim-collab-disclo-FAnX4DKBfor more information.
- cisco-sa-prim-collab-disclo-FAnX4DKB -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-prim-collab-disclo-FAnX4DKB - cisco-sa-prime-collab-xss-RjRCe9n7 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-prime-collab-xss-RjRCe9n7
CVEs related to QID 13942
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-prime-collab-xss-RjRCe9n7 |
|