9.1
CVSSv3

CVE-2019-1662

Published: 21/02/2019 Updated: 09/10/2019
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated, remote malicious user to access the system as a valid user. The vulnerability is due to insufficient authentication controls. An attacker could exploit this vulnerability by connecting to the QOVR service with a valid username. A successful exploit could allow the malicious user to perform actions with the privileges of the user that is used for access. This vulnerability affects Cisco PCA Software Releases before 12.1 SP2.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco prime collaboration assurance 12.1

cisco prime collaboration assurance

Vendor Advisories

A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated, remote attacker to access the system as a valid user The vulnerability is due to insufficient authentication controls An attacker could exploit this vulnerability by connecting to the QOVR service ...