Arbitrary file download in Cisco Prime Collaboration Assurance - CVE-2017-3843
Published: February 15, 2017 / Updated: February 17, 2017
Cisco Prime Collaboration Assurance
Detailed vulnerability description
The vulnerability allows a remote attacker to download system files.
The vulnerability exists due to improper input validation when processing HTTP requests. A remote attacker can send a specially crafted HTTP request and download arbitrary system files.
Successful exploitation of the vulnerability may allow an attacker access potentially sensitive information.