
====================================================================

                              CERT-Renater

                  Note d'Information No. 2016/VULN270
_____________________________________________________________________

DATE                : 30/06/2016

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Cisco Prime Collaboration Provisioning software.

=====================================================================
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160629-cpcpauthbypass
____________________________________________________________________

Cisco Prime Collaboration Provisioning Lightweight Directory Access
Protocol Authentication Bypass Vulnerability

Advisory ID: cisco-sa-20160629-cpcpauthbypass

Revision 1.0

For Public Release 2016 June 29 16:00 UTC (GMT)

+---------------------------------------------------------------------

Summary
=======

A vulnerability in the Lightweight Directory Access Protocol (LDAP)
authentication for Cisco Prime Collaboration Provisioning could allow
an unauthenticated, remote attacker to bypass authentication. The
attacker could be granted full administrator privileges.

The vulnerability is due to an improper implementation of LDAP
authentication. An attacker could exploit this vulnerability by
logging into a targeted device that is configured for LDAP
authentication. Successful exploitation of this vulnerability
could grant the attacker full administrator privileges.

Cisco has released software updates that address this vulnerability.
There are no workarounds that address this vulnerability.

This advisory is available at the following link:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160629-cpcpauthbypass

==========================================================
Serveur de référence du CERT-Renater
https://services.renater.fr/ssi/
==========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44           +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41           +
+ 75013 Paris           | email: cert@support.renater.fr +
==========================================================




