The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of an authenticated session, which allows remote attackers to discover usernames and passwords via an HTTP request, aka Bug ID CSCud32600.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Prime_central_for_hosted_collaboration_solution_assurance | Cisco | * | 9.1 (including) |
Prime_central_for_hosted_collaboration_solution_assurance | Cisco | 1.0 (including) | 1.0 (including) |
Prime_central_for_hosted_collaboration_solution_assurance | Cisco | 1.0.1 (including) | 1.0.1 (including) |
Prime_central_for_hosted_collaboration_solution_assurance | Cisco | 8.6 (including) | 8.6 (including) |
Prime_central_for_hosted_collaboration_solution_assurance | Cisco | 9.0 (including) | 9.0 (including) |