Directory listing in Cisco Prime Collaboration Assurance - CVE-2017-3844
Published: February 15, 2017 / Updated: February 17, 2017
Cisco Prime Collaboration Assurance
Detailed vulnerability description
The vulnerability allows a remote attacker to list and download system files.
The vulnerability exists due to improper input validation in Cisco Prime Collaboration Assurance when processing HTTP requests.A remote unauthenticated attacker can send a specially rcfated HTTP request and view list of files in directories.
Successful exploitation of the vulnerability may allow an attacker access potentially sensitive information.