Information disclosure in Elastic Services Controller - CVE-2017-6777

 

Information disclosure in Elastic Services Controller - CVE-2017-6777

Published: August 17, 2017


Vulnerability identifier: #VU7971
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6777
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information.

The vulnerability exists in the ConfD server of the Cisco Elastic Services Controller (ESC) due to insufficient protection of sensitive files. A remote attacker can log into the ConfD server and execute certain commands to view configuration parameters.

Successful exploitation of the vulnerability may result in further attacks.


Affected software

Elastic Services Controller

How to mitigate CVE-2017-6777

Install update from vendor's website.


External References

Related Security Bulletins