CVE-2017-6637
published 2017-05-22CVE-2017-6637: A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker…
PriorityP345medium6.5CVSS 3.0
AVNACLPRLUINSUCNIHAN
EPSS
7.84%
94.0th percentile
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker to delete any file from an affected system. The vulnerability exists because the affected software does not perform proper input validation of HTTP requests and fails to apply role-based access controls (RBACs) to requested HTTP URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request that uses directory traversal techniques to submit a path to a desired file location on an affected system. A successful exploit could allow the attacker to delete any file from the system. Cisco Bug IDs: CSCvc99618.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | prime_collaboration_provisioning | — | — |
| cisco | prime_collaboration_provisioning | — | — |
| cisco | prime_collaboration_provisioning | — | — |
| cisco | prime_collaboration_provisioning | — | — |
| cisco | prime_collaboration_provisioning | — | — |
| cisco | prime_collaboration_provisioning | — | — |
| cisco | prime_collaboration_provisioning | — | — |
| cisco | prime_collaboration_provisioning | — | — |
| cisco | prime_collaboration_provisioning_directory | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Prime Collaboration Provisioning Directory Traversal Arbitrary File Deletion Vulnerability
vendor_cisco·2017-05-17·CVSS 6.5
CVE-2017-6637 [MEDIUM] CWE-264 Cisco Prime Collaboration Provisioning Directory Traversal Arbitrary File Deletion Vulnerability
Cisco Prime Collaboration Provisioning Directory Traversal Arbitrary File Deletion Vulnerability
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software could allow an authenticated, remote attacker to delete any file from an affected system.
The vulnerability exists because the affected software does not perform proper input validation of HTTP requests and fails to apply role-based access controls (RBACs) to requested HTTP URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request that uses directory traversal techniques to submit a path to a desired file location on an affected system. A successful exploit could allow the attacker to delete any file from the system.
There are no workarounds that address this vulnerability.
Thi
Cisco
Cisco Prime Collaboration Provisioning Directory Traversal Arbitrary File Deletion Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-6637 Cisco Prime Collaboration Provisioning Directory Traversal Arbitrary File Deletion Vulnerability
CVE-2017-6637: Cisco Prime Collaboration Provisioning Directory Traversal Arbitrary File Deletion Vulnerability
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software could allow an authenticated, remote attacker to delete any file from an affected system. The vulnerability exists because the affected software does not perform proper input validation of HTTP requests and fails to apply role-based access controls (RBACs) to requested HTTP URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request that uses directory traversal techniques to submit a path to a desired file location on an affected system. A successful exploit could allow the attacker to delete any file from the system. There are no
CVSS: 3.0
CWE: CWE-264, CWE-264
Bug I
GHSA
GHSA-55v6-qp6h-3g38: A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11
ghsa_unreviewed·2022-05-13
CVE-2017-6637 [MEDIUM] CWE-20 GHSA-55v6-qp6h-3g38: A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker to delete any file from an affected system. The vulnerability exists because the affected software does not perform proper input validation of HTTP requests and fails to apply role-based access controls (RBACs) to requested HTTP URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request that uses directory traversal techniques to submit a path to a desired file location on an affected system. A successful exploit could allow the attacker to delete any file from the system. Cisco Bug IDs: CSCvc99618.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/98530http://www.securitytracker.com/id/1038515https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170517-pcp5http://www.securityfocus.com/bid/98530http://www.securitytracker.com/id/1038515https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170517-pcp5
2017-05-22
Published