Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2018-15438— Cisco Prime Collaboration Assurance Cross-Site Request Forgery Vulnerability

Quick assessment

Affected
Cisco Cisco Prime Collaboration Assurance
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Cisco Prime Collaboration Assurance(PCA)是美国思科(Cisco)公司的一套企业协作网络管理解决方案。该方案支持通过统一管理控制台简化统一通信和视频协作网络的管理,以及快速部署通信站点等。 Cisco PCA中的基于Web的管理界面存在跨站请求伪造漏洞。远程攻击者可通过诱使用户点击恶意链接利用该漏洞使用用户的web浏览器,以用户的权限在受影响的系统上执行任意操作。

AI Predicted 6.5 Difficulty: Easy EPSS 1.17% · P66
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2018-15438

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco Prime Collaboration Assurance Cross-Site Request Forgery Vulnerability
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to use a web browser to perform arbitrary actions with the privileges of the user on an affected system.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
跨站请求伪造(CSRF)
Source: CVE Program / CVE List V5
Vulnerability Title
Cisco Prime Collaboration Assurance 跨站请求伪造漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco Prime Collaboration Assurance(PCA)是美国思科(Cisco)公司的一套企业协作网络管理解决方案。该方案支持通过统一管理控制台简化统一通信和视频协作网络的管理,以及快速部署通信站点等。 Cisco PCA中的基于Web的管理界面存在跨站请求伪造漏洞。远程攻击者可通过诱使用户点击恶意链接利用该漏洞使用用户的web浏览器,以用户的权限在受影响的系统上执行任意操作。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Cisco Cisco Prime Collaboration Assurance n/a -

II. Public POCs for CVE-2018-15438

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-15438

登录查看更多情报信息。

Vendor Advisories for CVE-2018-15438 (3)

Same Patch Batch · Cisco · 2018-10-17 · 15 CVEs total

CVE-2018-0388 Cisco Wireless LAN Controller Software Cross-Site Scripting Vulnerability
CVE-2018-0416 Cisco Wireless LAN Controller Software Information Disclosure Vulnerability
CVE-2018-0395 Cisco FXOS and NX-OS Software Link Layer Discovery Protocol Denial of Service Vulnerabilit
CVE-2018-0456 Cisco NX-OS Software Authenticated Simple Network Management Protocol Denial of Service Vu
CVE-2018-15395 Cisco Wireless LAN Controller Software Privilege Escalation Vulnerability
CVE-2018-15402 Cisco Enterprise NFV Infrastructure Software Cross-Site Request Forgery Vulnerability
CVE-2018-0378 Cisco NX-OS Software for Nexus 5500, 5600, and 6000 Series Switches Precision Time Protoco
CVE-2018-0417 Cisco Wireless LAN Controller Software GUI Privilege Escalation Vulnerability
CVE-2018-0381 Cisco Aironet 1560, 1800, 2800, and 3800 Series Access Points Denial of Service Vulnerabil
CVE-2018-0420 Cisco Wireless LAN Controller Software Directory Traversal Vulnerability
CVE-2018-0441 Cisco IOS Access Points Software 802.11r Fast Transition Denial of Service Vulnerability
CVE-2018-0442 Cisco Wireless LAN Controller Software Control and Provisioning of Wireless Access Points
CVE-2018-0443 Cisco Wireless LAN Controller Software Control and Provisioning of Wireless Access Points
CVE-2018-15435 Cisco SocialMiner Cross-Site Scripting Vulnerability

IV. Related Vulnerabilities

V. Comments for CVE-2018-15438

No comments yet


Leave a comment