Information disclosure in Elastic Services Controller - CVE-2017-6777
Published: August 17, 2017
Elastic Services Controller
Detailed vulnerability description
The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information.
The vulnerability exists in the ConfD server of the Cisco Elastic Services Controller (ESC) due to insufficient protection of sensitive files. A remote attacker can log into the ConfD server and execute certain commands to view configuration parameters.
Successful exploitation of the vulnerability may result in further attacks.