Information disclosure in Cisco Ultra Services Framework - CVE-2017-6771
Published: August 17, 2017
Cisco Ultra Services Framework
Detailed vulnerability description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists in the AutoVNF automation tool of the Cisco Ultra Services Framework due to insufficient protection of sensitive data. A remote attacker can browse to a specific URL of an affected device and view sensitive configuration information about the deployment.
Successful exploitation of the vulnerability results in information disclosure.