QID 730129

Date Published: 2021-07-22

QID 730129: Cisco Prime Collaboration Assurance Lasso SAML Implementation Vulnerability (cisco-sa-lasso-saml-jun2021-DOXNRLkD)

On June 1, 2021, Lasso disclosed a security vulnerability in the Lasso Security Assertion Markup Language (SAML) Single Sign-On (SSO) library.

Affected Products:
Cisco Prime Collaboration Assurance, if running following vulnerable release:
i. Prior to 12.1 SP4 ES
ii. 12.1 SP5

QID Detection Logic (unauthenticated):
The QID matches the Vulnerable versions of Cisco PCA Software by sending HTTP GET request to '/emsam/index.html'.

This vulnerability could allow an authenticated attacker to impersonate another authorized user when interacting with an application.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-lasso-saml-jun2021-DOXNRLkD for more information.

    CVEs related to QID 730129

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-lasso-saml-jun2021-DOXNRLkD URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-lasso-saml-jun2021-DOXNRLkD