CVE-2017-6682

Severity
8.8HIGH
EPSS
1.0%
top 23.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 17

Description

A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to run arbitrary commands as the Linux tomcat user on an affected system. More Information: CSCvc76620. Known Affected Releases: 2.2(9.76).

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5cisco_elastic_services_controllerCisco Elastic Services Controller

🔴Vulnerability Details

2
GHSA
GHSA-3jrw-43cp-6whq: A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to run arbitrary commands as the2022-05-17
CVEList
CVE-2017-6682: A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to run arbitrary commands as the2017-06-13

📋Vendor Advisories

1
Cisco
Cisco Elastic Services Controller Arbitrary Command Execution Vulnerability2017-06-07
CVE-2017-6682 (HIGH CVSS 8.8) | A vulnerability in the ConfD CLI of | cvebase.io