CVE-2017-3843
published 2017-02-22CVE-2017-3843: A vulnerability in the file download functions for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to download system files…
PriorityP423medium4.3CVSS 3.0
AVNACLPRLUINSUCLINAN
EPSS
1.49%
71.1th percentile
A vulnerability in the file download functions for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to download system files that should be restricted. More Information: CSCvc99446. Known Affected Releases: 11.5(0).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | prime_collaboration_assurance | — | — |
| cisco | prime_collaboration_assurance | — | — |
| cisco | prime_collaboration_assurance | — | — |
| cisco | prime_collaboration_assurance | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p28f-wv4w-g7vp: A vulnerability in the file download functions for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to download syste
ghsa_unreviewed·2022-05-17
CVE-2017-3843 [MEDIUM] CWE-20 GHSA-p28f-wv4w-g7vp: A vulnerability in the file download functions for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to download syste
A vulnerability in the file download functions for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to download system files that should be restricted. More Information: CSCvc99446. Known Affected Releases: 11.5(0).
Cisco
Cisco Prime Collaboration Assurance Arbitrary File Download Vulnerability
vendor_cisco·2017-02-15·CVSS 4.3
CVE-2017-3843 [MEDIUM] CWE-20 Cisco Prime Collaboration Assurance Arbitrary File Download Vulnerability
Cisco Prime Collaboration Assurance Arbitrary File Download Vulnerability
A vulnerability in the file download functions for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to download system files that should be restricted.
The vulnerability is due to lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the targeted application. An exploit could allow the attacker to download system files that should be restricted.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-pcp1
Cisco
Cisco Prime Collaboration Assurance Arbitrary File Download Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-3843 Cisco Prime Collaboration Assurance Arbitrary File Download Vulnerability
CVE-2017-3843: Cisco Prime Collaboration Assurance Arbitrary File Download Vulnerability
A vulnerability in the file download functions for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to download system files that should be restricted. The vulnerability is due to lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the targeted application. An exploit could allow the attacker to download system files that should be restricted. There are no
CVSS: 3.0
CWE: CWE-20, CWE-20
Bug IDs: CSCvc99446
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/96248http://www.securitytracker.com/id/1037843https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-pcp1http://www.securityfocus.com/bid/96248http://www.securitytracker.com/id/1037843https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-pcp1
2017-02-22
Published