CVE Database
/

CVE-2017-6622

Back to search

CVE-2017-6622

Published: May 18, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges. The vulnerability is due to missing security constraints in certain HTTP request methods, which could allow access to files via the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the targeted application. This vulnerability affects Cisco Prime Collaboration Provisioning Software Releases prior to 12.1. Cisco Bug IDs: CSCvc98724.

VendorProductVersions

n/a

Cisco Prime Collaboration Provisioning

affected
Cisco Prime Collaboration Provisioning

Weaknesses (CWE)

References

1038507
vdb-entry
x_refsource_SECTRACK
98520
vdb-entry
x_refsource_BID
42888
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now