CVE-2017-3844
published 2017-02-22CVE-2017-3844: A vulnerability in exporting functions of the user interface for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to view file…
PriorityP424medium4.3CVSS 3.0
AVNACLPRLUINSUCLINAN
EPSS
1.49%
71.1th percentile
A vulnerability in exporting functions of the user interface for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to view file directory listings and download files. Affected Products: Cisco Prime Collaboration Assurance software versions 11.0, 11.1, and 11.5 are vulnerable. Cisco Prime Collaboration Assurance software versions prior to 11.0 are not vulnerable. More Information: CSCvc86238. Known Affected Releases: 11.5(0).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | prime_collaboration_assurance | — | — |
| cisco | prime_collaboration_assurance | — | — |
| cisco | prime_collaboration_assurance | — | — |
| cisco | prime_collaboration_assurance_directory_listing_unauthorized_access | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Prime Collaboration Assurance Directory Listing Unauthorized Access Vulnerability
vendor_cisco·2017-02-15·CVSS 4.3
CVE-2017-3844 [MEDIUM] CWE-20 Cisco Prime Collaboration Assurance Directory Listing Unauthorized Access Vulnerability
Cisco Prime Collaboration Assurance Directory Listing Unauthorized Access Vulnerability
A vulnerability in exporting functions of the user interface for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to view file directory listings and download files.
The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability sending a crafted HTTP request to the targeted application. An exploit could allow the attacker to view and download system files that should be restricted.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-pcp2
Cisco
Cisco Prime Collaboration Assurance Directory Listing Unauthorized Access Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-3844 Cisco Prime Collaboration Assurance Directory Listing Unauthorized Access Vulnerability
CVE-2017-3844: Cisco Prime Collaboration Assurance Directory Listing Unauthorized Access Vulnerability
A vulnerability in exporting functions of the user interface for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to view file directory listings and download files. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability sending a crafted HTTP request to the targeted application. An exploit could allow the attacker to view and download system files that should be restricted. There are no
CVSS: 3.0
CWE: CWE-20, CWE-20
Bug IDs: CSCvc86238
GHSA
GHSA-hcf3-m8fc-xfmv: A vulnerability in exporting functions of the user interface for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to
ghsa_unreviewed·2022-05-17
CVE-2017-3844 [MEDIUM] CWE-20 GHSA-hcf3-m8fc-xfmv: A vulnerability in exporting functions of the user interface for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to
A vulnerability in exporting functions of the user interface for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to view file directory listings and download files. Affected Products: Cisco Prime Collaboration Assurance software versions 11.0, 11.1, and 11.5 are vulnerable. Cisco Prime Collaboration Assurance software versions prior to 11.0 are not vulnerable. More Information: CSCvc86238. Known Affected Releases: 11.5(0).
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Multiple Foscam C1 Vulnerabilities Come in to Focus
blogs_talos·2017-06-19·CVSS 9.8
[CRITICAL] Vulnerability Spotlight: Multiple Foscam C1 Vulnerabilities Come in to Focus
## Vulnerability Spotlight: Multiple Foscam C1 Vulnerabilities Come in to Focus
## Executive Summary The Foscam C1 is a webcam that is marketed for use in a variety of applications including home security monitoring. As an indoor webcam, it is designed to be set up inside of a building and features the ability to be accessed remotely via a web interface or from within a mobile application. Talos recently identified several vulnerabilities in the Foscam C1 camera that could be used by attackers for a variety of purposes including access and retrieval of sensitive information stored on the camera, execution of arbitrary commands within the camera's operating system, and in several cases, completely compromise the device. As these cameras are commonly deployed in sensitive locations and used
Talos
Vulnerability Spotlight: Multiple Foscam C1 Vulnerabilities Come in to Focus
blogs_talos·2017-06-19·CVSS 9.8
[CRITICAL] Vulnerability Spotlight: Multiple Foscam C1 Vulnerabilities Come in to Focus
## Executive Summary The Foscam C1 is a webcam that is marketed for use in a variety of applications including home security monitoring. As an indoor webcam, it is designed to be set up inside of a building and features the ability to be accessed remotely via a web interface or from within a mobile application. Talos recently identified several vulnerabilities in the Foscam C1 camera that could be used by attackers for a variety of purposes including access and retrieval of sensitive information stored on the camera, execution of arbitrary commands within the camera's operating system, and in several cases, completely compromise the device. As these cameras are commonly deployed in sensitive locations and used as baby monitors, security cameras, etc. it is recommended that affected devices
http://www.securityfocus.com/bid/96247http://www.securitytracker.com/id/1037843https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-pcp2http://www.securityfocus.com/bid/96247http://www.securitytracker.com/id/1037843https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-pcp2
2017-02-22
Published