A vulnerability was found in Cisco Prime Collaboration Assurance (the affected version is unknown). It has been declared as problematic. This vulnerability affects an unknown function of the component Web-based Management Interface. The manipulation with an unknown input leads to a cross site request forgery vulnerability. The CWE definition for the vulnerability is CWE-352. As an impact it is known to affect integrity. An attacker might be able force legitimate users to initiate unwanted actions within the web application.
The weakness was presented 10/17/2018 as cisco-sa-20181017-cpca-csrf as confirmed advisory (Website). The advisory is shared for download at tools.cisco.com. This vulnerability was named CVE-2018-15438 since 08/17/2018. The attack can be initiated remotely. No form of authentication is required for a successful exploitation. There are neither technical details nor an exploit publicly available. The current price for an exploit might be approx. USD $5k-$25k (estimation calculated on 10/18/2018).
There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.
CPE
CVSSv3
VulDB Meta Base Score: 5.3
VulDB Meta Temp Score: 5.3
VulDB Base Score:
5.3VulDB Temp Score:
5.3VulDB Vector:
🔒VulDB Reliability:
🔍CVSSv2
VulDB Base Score:
🔒VulDB Temp Score:
🔒VulDB Reliability:
🔍Exploiting
Class: Cross site request forgery (
CWE-352)
Local: No
Remote: Yes
Availability: No
Price Prediction:
🔍Current Price Estimation:
🔒Threat Intelligence
Threat:
🔍Adversaries:
🔍Geopolitics:
🔍Economy:
🔍Predictions:
🔍Actions:
🔍Countermeasures
Recommended: no mitigation known
0-Day Time:
🔒Timeline
08/17/2018 CVE assigned10/17/2018 Advisory disclosed10/18/2018 VulDB entry created10/18/2018 VulDB last updateSources
Advisory:
cisco-sa-20181017-cpca-csrfStatus: Confirmed
CVE:
CVE-2018-15438 (
🔒)
Entry
Created: 10/18/2018
Complete:
🔍Lien vers l'article source