Symlink Vulnerability in Cisco Ultra Services Framework
CVE-2017-6708
9.8CRITICAL
Summary
This vulnerability in the AutoVNF tool associated with the Cisco Ultra Services Framework arises from inadequate validation checks during symlink creation. An attacker, without authentication, can exploit this flaw to access sensitive files or execute code maliciously, compromising the integrity and confidentiality of the affected system. It impacts all versions of the framework prior to the updates in Releases 5.0.3 and 5.1, highlighting the importance of timely patching and system auditing to mitigate risks.
Affected Version(s)
Cisco Ultra Services Framework Cisco Ultra Services Framework
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved