Symlink Vulnerability in Cisco Ultra Services Framework
CVE-2017-6708

9.8CRITICAL

Key Information:

Vendor
Cisco
Vendor
CVE Published:
6 July 2017

Summary

This vulnerability in the AutoVNF tool associated with the Cisco Ultra Services Framework arises from inadequate validation checks during symlink creation. An attacker, without authentication, can exploit this flaw to access sensitive files or execute code maliciously, compromising the integrity and confidentiality of the affected system. It impacts all versions of the framework prior to the updates in Releases 5.0.3 and 5.1, highlighting the importance of timely patching and system auditing to mitigate risks.

Affected Version(s)

Cisco Ultra Services Framework Cisco Ultra Services Framework

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.