Information disclosure in Elastic Services Controller - CVE-2017-6772

 

Information disclosure in Elastic Services Controller - CVE-2017-6772

Published: August 17, 2017


Vulnerability identifier: #VU7973
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6772
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information.

The vulnerability exists in Cisco Elastic Services Controller (ESC) due to insufficient protection of sensitive data. A remote attacker can authenticate to the application and navigate to certain configuration files.

Successful exploitation of the vulnerability may result in further attacks.


Affected software

Elastic Services Controller

How to mitigate CVE-2017-6772

Install update from vendor's website.


External References

Related Security Bulletins