CVE-2018-0141
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software 11.6 could allow an unauthenticated, local attacker to log in to the underlying Linux operating system. The vulnerability is due to a hard-coded account password on the system. An attacker could exploit this vulnerability by connecting to the affected system via Secure Shell (SSH) using the hard-coded credentials. A successful exploit could allow the attacker to access the underlying operating system as a low-privileged user. After low-level privileges are gained, the attacker could elevate to root privileges and take full control of the device. Cisco Bug IDs: CSCvc82982.
Una vulnerabilidad en Cisco Prime Collaboration Provisioning (PCP) Software 11.6 podría permitir que un atacante local no autenticado inicie sesión en el sistema operativo Linux subyacente. Esta vulnerabilidad se debe a una contraseña de cuenta embebida en el sistema. Un atacante podría explotar esta vulnerabilidad conectándose al sistema afectado mediante SSH (Secure Shell) utilizando las credenciales embebidas. Una explotación con éxito podría permitir que el atacante acceda al sistema operativo subyacente como usuario con privilegios bajos. Después de que se obtengan los privilegios de bajo nivel, el atacante podría elevarlos a root y tomar el control total del dispositivo. Cisco Bug IDs: CSCvc82982.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-11-27 CVE Reserved
- 2018-03-08 CVE Published
- 2023-09-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-798: Use of Hard-coded Credentials
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/103329 | Third Party Advisory | |
http://www.securitytracker.com/id/1040462 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180307-cpcp | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Prime Collaboration Search vendor "Cisco" for product "Prime Collaboration" | 11.6 Search vendor "Cisco" for product "Prime Collaboration" and version "11.6" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Prime Collaboration Assurance Search vendor "Cisco" for product "Prime Collaboration Assurance" | 11.6 Search vendor "Cisco" for product "Prime Collaboration Assurance" and version "11.6" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Prime Collaboration Provisioning Search vendor "Cisco" for product "Prime Collaboration Provisioning" | 11.6 Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "11.6" | - |
Affected
|