Arbitrary file download in Cisco Prime Collaboration Assurance - CVE-2017-3843

 

Arbitrary file download in Cisco Prime Collaboration Assurance - CVE-2017-3843

Published: February 15, 2017 / Updated: February 17, 2017


Vulnerability identifier: #VU5857
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-3843
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to download system files.

The vulnerability exists due to improper input validation when processing HTTP requests. A remote attacker can send a specially crafted HTTP request and download arbitrary system files.

Successful exploitation of the vulnerability may allow an attacker access potentially sensitive information.


Affected software

Cisco Prime Collaboration Assurance

How to mitigate CVE-2017-3843

Install update from vendor's website.


External References

Related Security Bulletins