// For flags

CVE-2017-6622

Cisco Prime Collaboration Provisioning ScriptMgr Servlet Authentication Bypass Remote Code Execution Vulnerability

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges. The vulnerability is due to missing security constraints in certain HTTP request methods, which could allow access to files via the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the targeted application. This vulnerability affects Cisco Prime Collaboration Provisioning Software Releases prior to 12.1. Cisco Bug IDs: CSCvc98724.

Una vulnerabilidad en la interfaz web de Cisco Prime Collaboration Provisioning podría permitir que un atacante remoto no autenticado omita la autenticación y realice una inyección de comandos con privilegios root. La vulnerabilidad se debe a la falta de restricciones de seguridad en ciertos métodos de peticiones HTTP, lo que podría permitir el acceso a archivos mediante la interfaz web. Un atacante podría explotar esta vulnerabilidad mediante el envío de una petición HTTP manipulada a la aplicación objetivo. Esta vulnerabilidad afecta a las distribuciones del software Cisco Prime Collaboration Provisioning anteriores a la 12.1. Cisco Bug IDs: CSCvc98724.

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Cisco Prime Collaboration Provisioning. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the ScriptMgr servlet, which listens on TCP port 443 by default. A crafted request can bypass authentication for this resource. An attacker can leverage this vulnerability to execute arbitrary code under the context of root.

Cisco Prime Collaboration Provisioning versions prior to 12.1 suffer from authentication bypass and code execution vulnerabilities.

*Credits: rgod
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-03-09 CVE Reserved
  • 2017-05-18 CVE Published
  • 2024-08-05 CVE Updated
  • 2024-08-05 First Exploit
  • 2024-10-28 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
  • CWE-862: Missing Authorization
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Prime Collaboration Provisioning
Search vendor "Cisco" for product "Prime Collaboration Provisioning"
9.0.0
Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "9.0.0"
-
Affected
Cisco
Search vendor "Cisco"
Prime Collaboration Provisioning
Search vendor "Cisco" for product "Prime Collaboration Provisioning"
9.5.0
Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "9.5.0"
-
Affected
Cisco
Search vendor "Cisco"
Prime Collaboration Provisioning
Search vendor "Cisco" for product "Prime Collaboration Provisioning"
10.0.0
Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "10.0.0"
-
Affected
Cisco
Search vendor "Cisco"
Prime Collaboration Provisioning
Search vendor "Cisco" for product "Prime Collaboration Provisioning"
10.5.0
Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "10.5.0"
-
Affected
Cisco
Search vendor "Cisco"
Prime Collaboration Provisioning
Search vendor "Cisco" for product "Prime Collaboration Provisioning"
10.5.1
Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "10.5.1"
-
Affected
Cisco
Search vendor "Cisco"
Prime Collaboration Provisioning
Search vendor "Cisco" for product "Prime Collaboration Provisioning"
10.6.0
Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "10.6.0"
-
Affected
Cisco
Search vendor "Cisco"
Prime Collaboration Provisioning
Search vendor "Cisco" for product "Prime Collaboration Provisioning"
10.6.2
Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "10.6.2"
-
Affected
Cisco
Search vendor "Cisco"
Prime Collaboration Provisioning
Search vendor "Cisco" for product "Prime Collaboration Provisioning"
11.0.0
Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "11.0.0"
-
Affected
Cisco
Search vendor "Cisco"
Prime Collaboration Provisioning
Search vendor "Cisco" for product "Prime Collaboration Provisioning"
11.1.0
Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "11.1.0"
-
Affected
Cisco
Search vendor "Cisco"
Prime Collaboration Provisioning
Search vendor "Cisco" for product "Prime Collaboration Provisioning"
11.5.0
Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "11.5.0"
-
Affected