7.5
CVE-2017-6621
- EPSS 3.82%
- Veröffentlicht 18.05.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle psirt@cisco.com
- CVE-Watchlists
- Unerledigt
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to insufficient protection of sensitive data when responding to an HTTP request on the web interface. An attacker could exploit the vulnerability by sending a crafted HTTP request to the application to access specific system files. An exploit could allow the attacker to obtain sensitive information about the application which could include user credentials. This vulnerability affects Cisco Prime Collaboration Provisioning Software Releases 10.6 through 11.5. Cisco Bug IDs: CSCvc99626.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Prime Collaboration Provisioning Version9.0.0
Cisco ≫ Prime Collaboration Provisioning Version9.5.0
Cisco ≫ Prime Collaboration Provisioning Version10.0.0
Cisco ≫ Prime Collaboration Provisioning Version10.5.0
Cisco ≫ Prime Collaboration Provisioning Version10.5.1
Cisco ≫ Prime Collaboration Provisioning Version10.6.0
Cisco ≫ Prime Collaboration Provisioning Version10.6.2
Cisco ≫ Prime Collaboration Provisioning Version11.0.0
Cisco ≫ Prime Collaboration Provisioning Version11.1.0
Cisco ≫ Prime Collaboration Provisioning Version11.5.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.82% | 0.87 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.