9.8
CVSSv3

CVE-2018-0321

Published: 07/06/2018 Updated: 09/10/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote malicious user to access the Java Remote Method Invocation (RMI) system. The vulnerability is due to an open port in the Network Interface and Configuration Engine (NICE) service. An attacker could exploit this vulnerability by accessing the open RMI system on an affected PCP instance. An exploit could allow the malicious user to perform malicious actions that affect PCP and the devices that are connected to it. This vulnerability affects Cisco Prime Collaboration Provisioning (PCP) Releases 11.6 and prior. Cisco Bug IDs: CSCvd61746.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco prime collaboration assurance

cisco prime collaboration

cisco prime collaboration provisioning

Vendor Advisories

A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invocation (RMI) system The vulnerability is due to an open port in the Network Interface and Configuration Engine (NICE) service An attacker could exploit this vulnerability by accessing the open RMI sy ...