Unauthorized Directory Access in Cisco Elastic Services Controllers
CVE-2017-6693

5.5MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
13 June 2017

Summary

A vulnerability in the ConfD server component of Cisco Elastic Services Controllers enables authenticated local attackers to improperly gain access to sensitive information stored within the file system. This security flaw could expose critical data, allowing malicious actors to exploit the affected systems. Users of versions 2.2(9.76) and 2.3(1) are particularly at risk and should take immediate action to mitigate potential threats.

Affected Version(s)

Cisco Elastic Services Controller Cisco Elastic Services Controller

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.