CVE-2018-0204
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for individual users. The vulnerability is due to weak login controls. An attacker could exploit this vulnerability by using a brute-force attack (Repeated Bad Login Attempts). A successful exploit could allow the attacker to restrict user access. Manual administrative intervention is required to restore access. Cisco Bug IDs: CSCvd07264.
Una vulnerabilidad en el portal web de Cisco Prime Collaboration Provisioning Tool podría permitir que un atacante remoto no autenticado cree una condición de denegación de servicio (DoS) para usuarios individuales. La vulnerabilidad se debe a controles de inicio de sesión débiles. Un atacante podría explotar esta vulnerabilidad mediante un ataque de fuerza bruta (repetición de intentos de inicio de sesión fallidos). Una explotación con éxito podría permitir a un atacante restringir el acceso a los usuarios. Se requiere intervención administrativa manual para restablecer el acceso. Cisco Bug IDs: CSCvd07264.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-11-27 CVE Reserved
- 2018-02-22 CVE Published
- 2023-08-24 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-521: Weak Password Requirements
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/103150 | Third Party Advisory | |
http://www.securitytracker.com/id/1040410 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180221-pcpt | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Prime Collaboration Provisioning Search vendor "Cisco" for product "Prime Collaboration Provisioning" | 12.1 Search vendor "Cisco" for product "Prime Collaboration Provisioning" and version "12.1" | - |
Affected
|