CVE-2017-6636
published 2017-05-22CVE-2017-6636: A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker…
PriorityP342medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
5.88%
92.4th percentile
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker to view any file on an affected system. The vulnerability exists because the affected software does not perform proper input validation of HTTP requests and fails to apply role-based access controls (RBACs) to requested HTTP URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request that uses directory traversal techniques to submit a path to a desired file location on an affected system. A successful exploit could allow the attacker to view any file on the system. Cisco Bug IDs: CSCvc99604.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | prime_collaboration_provisioning | — | — |
| cisco | prime_collaboration_provisioning | — | — |
| cisco | prime_collaboration_provisioning | — | — |
| cisco | prime_collaboration_provisioning | — | — |
| cisco | prime_collaboration_provisioning | — | — |
| cisco | prime_collaboration_provisioning | — | — |
| cisco | prime_collaboration_provisioning | — | — |
| cisco | prime_collaboration_provisioning | — | — |
| cisco | prime_collaboration_provisioning_directory | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x379-2rh4-mvpr: A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11
ghsa_unreviewed·2022-05-17
CVE-2017-6636 [MEDIUM] CWE-22 GHSA-x379-2rh4-mvpr: A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker to view any file on an affected system. The vulnerability exists because the affected software does not perform proper input validation of HTTP requests and fails to apply role-based access controls (RBACs) to requested HTTP URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request that uses directory traversal techniques to submit a path to a desired file location on an affected system. A successful exploit could allow the attacker to view any file on the system. Cisco Bug IDs: CSCvc99604.
Cisco
Cisco Prime Collaboration Provisioning Directory Traversal Information Disclosure Vulnerability
vendor_cisco·2017-05-17·CVSS 6.5
CVE-2017-6636 [MEDIUM] CWE-22 Cisco Prime Collaboration Provisioning Directory Traversal Information Disclosure Vulnerability
Cisco Prime Collaboration Provisioning Directory Traversal Information Disclosure Vulnerability
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software could allow an authenticated, remote attacker to view any file on an affected system.
The vulnerability exists because the affected software does not perform proper input validation of HTTP requests and fails to apply role-based access controls (RBACs) to requested HTTP URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request that uses directory traversal techniques to submit a path to a desired file location on an affected system. A successful exploit could allow the attacker to view any file on the system.
There are no workarounds that address this vulnerability.
This advisor
Cisco
Cisco Prime Collaboration Provisioning Directory Traversal Information Disclosure Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-6636 Cisco Prime Collaboration Provisioning Directory Traversal Information Disclosure Vulnerability
CVE-2017-6636: Cisco Prime Collaboration Provisioning Directory Traversal Information Disclosure Vulnerability
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software could allow an authenticated, remote attacker to view any file on an affected system. The vulnerability exists because the affected software does not perform proper input validation of HTTP requests and fails to apply role-based access controls (RBACs) to requested HTTP URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request that uses directory traversal techniques to submit a path to a desired file location on an affected system. A successful exploit could allow the attacker to view any file on the system. There are no
CVSS: 3.0
CWE: CWE-22, CWE-22
Bug IDs: CSCvc99
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/98526http://www.securitytracker.com/id/1038515https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170517-pcp4http://www.securityfocus.com/bid/98526http://www.securitytracker.com/id/1038515https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170517-pcp4
2017-05-22
Published