CVE-2017-6622
Cisco Prime Collaboration Provisioning ScriptMgr Servlet Authentication Bypass Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges. The vulnerability is due to missing security constraints in certain HTTP request methods, which could allow access to files via the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the targeted application. This vulnerability affects Cisco Prime Collaboration Provisioning Software Releases prior to 12.1. Cisco Bug IDs: CSCvc98724.
Una vulnerabilidad en la interfaz web de Cisco Prime Collaboration Provisioning podría permitir que un atacante remoto no autenticado omita la autenticación y realice una inyección de comandos con privilegios root. La vulnerabilidad se debe a la falta de restricciones de seguridad en ciertos métodos de peticiones HTTP, lo que podría permitir el acceso a archivos mediante la interfaz web. Un atacante podría explotar esta vulnerabilidad mediante el envío de una petición HTTP manipulada a la aplicación objetivo. Esta vulnerabilidad afecta a las distribuciones del software Cisco Prime Collaboration Provisioning anteriores a la 12.1. Cisco Bug IDs: CSCvc98724.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Cisco Prime Collaboration Provisioning. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the ScriptMgr servlet, which listens on TCP port 443 by default. A crafted request can bypass authentication for this resource. An attacker can leverage this vulnerability to execute arbitrary code under the context of root.
Cisco Prime Collaboration Provisioning versions prior to 12.1 suffer from authentication bypass and code execution vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-03-09 CVE Reserved
- 2017-05-18 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-10-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
- CWE-862: Missing Authorization
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/98520 | Third Party Advisory | |
http://www.securitytracker.com/id/1038507 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/42888 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170517-pcp1 | 2019-10-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Prime Collaboration Provisioning Search vendor "Cisco" for product "Prime Collaboration Provisioning" | 9.0.0 Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "9.0.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Prime Collaboration Provisioning Search vendor "Cisco" for product "Prime Collaboration Provisioning" | 9.5.0 Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "9.5.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Prime Collaboration Provisioning Search vendor "Cisco" for product "Prime Collaboration Provisioning" | 10.0.0 Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "10.0.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Prime Collaboration Provisioning Search vendor "Cisco" for product "Prime Collaboration Provisioning" | 10.5.0 Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "10.5.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Prime Collaboration Provisioning Search vendor "Cisco" for product "Prime Collaboration Provisioning" | 10.5.1 Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "10.5.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Prime Collaboration Provisioning Search vendor "Cisco" for product "Prime Collaboration Provisioning" | 10.6.0 Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "10.6.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Prime Collaboration Provisioning Search vendor "Cisco" for product "Prime Collaboration Provisioning" | 10.6.2 Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "10.6.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Prime Collaboration Provisioning Search vendor "Cisco" for product "Prime Collaboration Provisioning" | 11.0.0 Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "11.0.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Prime Collaboration Provisioning Search vendor "Cisco" for product "Prime Collaboration Provisioning" | 11.1.0 Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "11.1.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Prime Collaboration Provisioning Search vendor "Cisco" for product "Prime Collaboration Provisioning" | 11.5.0 Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "11.5.0" | - |
Affected
|