Privilege Escalation Vulnerability in Cisco Elastic Services Controller
CVE-2017-6712

8.8HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
6 July 2017

Summary

A security flaw in Cisco Elastic Services Controller allows an authenticated remote attacker to gain elevated privileges, potentially compromising the integrity of the server. This vulnerability arises from the ability of a 'tomcat' user to execute specific shell commands, which can overwrite files and escalate to root-level access. Users should update to versions 2.3.1.434 or 2.3.2 to mitigate the risks associated with this vulnerability.

Affected Version(s)

Cisco Elastic Services Controller Cisco Elastic Services Controller

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.