Remote Access Vulnerability in Cisco Ultra Services Framework
CVE-2017-6711
Summary
A vulnerability in the Ultra Automation Service of the Cisco Ultra Services Framework permits unauthenticated remote access, enabling attackers to infiltrate devices. The flaw arises from an insecure default configuration of the Apache ZooKeeper service integral to the framework. By leveraging this vulnerability, an attacker could access ZooKeeper data nodes (znodes) and manipulate the high-availability features of the system, posing significant risks to data integrity and availability. All earlier releases of the Cisco Ultra Services Framework UAS are impacted, necessitating immediate action for users to update to Releases 5.0.3 and 5.1 to mitigate potential threats.
Affected Version(s)
Cisco Ultra Services Framework Cisco Ultra Services Framework
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved