CVE-2017-6621Sensitive Information Exposure in Cisco Prime Collaboration Provisioning

Severity
7.5HIGHNVD
EPSS
3.8%
top 11.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 18
Latest updateMay 17

Description

A vulnerability in the web interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to insufficient protection of sensitive data when responding to an HTTP request on the web interface. An attacker could exploit the vulnerability by sending a crafted HTTP request to the application to access specific system files. An e

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-jv3h-mvmw-qgrw: A vulnerability in the web interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to access sensitive dat2022-05-17
CVEList
CVE-2017-6621: A vulnerability in the web interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to access sensitive dat2017-05-18

📋Vendor Advisories

1
Cisco
Cisco Prime Collaboration Provisioning Information Disclosure Vulnerability2017-05-17
CVE-2017-6621 — Sensitive Information Exposure in Cisco | cvebase