Information disclosure in Elastic Services Controller - CVE-2017-6772
Published: August 17, 2017
Elastic Services Controller
Detailed vulnerability description
The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information.
The vulnerability exists in Cisco Elastic Services Controller (ESC) due to insufficient protection of sensitive data. A remote attacker can authenticate to the application and navigate to certain configuration files.
Successful exploitation of the vulnerability may result in further attacks.