Path Traversal Vulnerability in Cisco Ultra Services Framework
CVE-2017-6681

7.5HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
13 June 2017

Summary

A vulnerability exists in the AutoVNF VNFStagingView class of Cisco's Ultra Services Framework that could be exploited by an unauthenticated remote attacker. By performing a relative path traversal attack, the attacker may gain unauthorized access to sensitive files stored on the system. This could lead to exposure of critical information and potential compromise of the system's integrity.

Affected Version(s)

Cisco Ultra Services Framework Cisco Ultra Services Framework

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.