CVE Database
/

CVE-2017-6621

Back to search

CVE-2017-6621

Published: May 18, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

A vulnerability in the web interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to insufficient protection of sensitive data when responding to an HTTP request on the web interface. An attacker could exploit the vulnerability by sending a crafted HTTP request to the application to access specific system files. An exploit could allow the attacker to obtain sensitive information about the application which could include user credentials. This vulnerability affects Cisco Prime Collaboration Provisioning Software Releases 10.6 through 11.5. Cisco Bug IDs: CSCvc99626.

VendorProductVersions

n/a

Cisco Prime Collaboration

affected
Cisco Prime Collaboration

Weaknesses (CWE)

References

1038508
vdb-entry
x_refsource_SECTRACK
98522
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now