Remote Access Vulnerability in Cisco Ultra Services Framework
CVE-2017-6711

9.1CRITICAL

Key Information:

Vendor
Cisco
Vendor
CVE Published:
6 July 2017

Summary

A vulnerability in the Ultra Automation Service of the Cisco Ultra Services Framework permits unauthenticated remote access, enabling attackers to infiltrate devices. The flaw arises from an insecure default configuration of the Apache ZooKeeper service integral to the framework. By leveraging this vulnerability, an attacker could access ZooKeeper data nodes (znodes) and manipulate the high-availability features of the system, posing significant risks to data integrity and availability. All earlier releases of the Cisco Ultra Services Framework UAS are impacted, necessitating immediate action for users to update to Releases 5.0.3 and 5.1 to mitigate potential threats.

Affected Version(s)

Cisco Ultra Services Framework Cisco Ultra Services Framework

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.