QID 730129
Date Published: 2021-07-22
QID 730129: Cisco Prime Collaboration Assurance Lasso SAML Implementation Vulnerability (cisco-sa-lasso-saml-jun2021-DOXNRLkD)
On June 1, 2021, Lasso disclosed a security vulnerability in the Lasso Security Assertion Markup Language (SAML) Single Sign-On (SSO) library.
Affected Products:
Cisco Prime Collaboration Assurance, if running following vulnerable release:
i. Prior to 12.1 SP4 ES
ii. 12.1 SP5
QID Detection Logic (unauthenticated):
The QID matches the Vulnerable versions of Cisco PCA Software by sending HTTP GET request to '/emsam/index.html'.
This vulnerability could allow an authenticated attacker to impersonate another authorized user when interacting with an application.
Solution
Customers are advised to refer to cisco-sa-lasso-saml-jun2021-DOXNRLkD for more information.
Vendor References
- cisco-sa-lasso-saml-jun2021-DOXNRLkD -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-lasso-saml-jun2021-DOXNRLkD
CVEs related to QID 730129
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-lasso-saml-jun2021-DOXNRLkD |
|