Privilege Escalation Vulnerability in Cisco Elastic Services Controller
CVE-2017-6712
8.8HIGH
Summary
A security flaw in Cisco Elastic Services Controller allows an authenticated remote attacker to gain elevated privileges, potentially compromising the integrity of the server. This vulnerability arises from the ability of a 'tomcat' user to execute specific shell commands, which can overwrite files and escalate to root-level access. Users should update to versions 2.3.1.434 or 2.3.2 to mitigate the risks associated with this vulnerability.
Affected Version(s)
Cisco Elastic Services Controller Cisco Elastic Services Controller
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved