10
CVE-2017-6622
- EPSS 77.35%
- Veröffentlicht 18.05.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle psirt@cisco.com
- CVE-Watchlists
- Unerledigt
A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges. The vulnerability is due to missing security constraints in certain HTTP request methods, which could allow access to files via the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the targeted application. This vulnerability affects Cisco Prime Collaboration Provisioning Software Releases prior to 12.1. Cisco Bug IDs: CSCvc98724.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Prime Collaboration Provisioning Version9.0.0
Cisco ≫ Prime Collaboration Provisioning Version9.5.0
Cisco ≫ Prime Collaboration Provisioning Version10.0.0
Cisco ≫ Prime Collaboration Provisioning Version10.5.0
Cisco ≫ Prime Collaboration Provisioning Version10.5.1
Cisco ≫ Prime Collaboration Provisioning Version10.6.0
Cisco ≫ Prime Collaboration Provisioning Version10.6.2
Cisco ≫ Prime Collaboration Provisioning Version11.0.0
Cisco ≫ Prime Collaboration Provisioning Version11.1.0
Cisco ≫ Prime Collaboration Provisioning Version11.5.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 77.35% | 0.989 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.