Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-6777

Опубликовано: 17 авг. 2017
Источник: nvd
CVSS3: 4.9
CVSS2: 4
EPSS Низкий

Описание

A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to acquire sensitive system information. The vulnerability is due to insufficient protection of sensitive files on the system. An attacker could exploit this vulnerability by logging into the ConfD server and executing certain commands. An exploit could allow an unprivileged user to view configuration parameters that can be maliciously used. Cisco Bug IDs: CSCvd76409. Known Affected Releases: 2.3, 2.3(2).

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:elastic_services_controller:2.3:*:*:*:*:*:*:*
cpe:2.3:a:cisco:elastic_services_controller:2.3\(2\):*:*:*:*:*:*:*

EPSS

Процентиль: 41%
0.00193
Низкий

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.9
github
больше 3 лет назад

A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to acquire sensitive system information. The vulnerability is due to insufficient protection of sensitive files on the system. An attacker could exploit this vulnerability by logging into the ConfD server and executing certain commands. An exploit could allow an unprivileged user to view configuration parameters that can be maliciously used. Cisco Bug IDs: CSCvd76409. Known Affected Releases: 2.3, 2.3(2).

EPSS

Процентиль: 41%
0.00193
Низкий

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200