CVE-2017-6683

Severity
8.8HIGH
EPSS
9.5%
top 7.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 17

Description

A vulnerability in the esc_listener.py script of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to execute arbitrary commands as the tomcat user on an affected system, aka an Authentication Request Processing Arbitrary Command Execution Vulnerability. More Information: CSCvc76642. Known Affected Releases: 2.2(9.76).

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5cisco_elastic_services_controllerCisco Elastic Services Controller

🔴Vulnerability Details

2
GHSA
GHSA-7w8x-vx5w-mg75: A vulnerability in the esc_listener2022-05-17
CVEList
CVE-2017-6683: A vulnerability in the esc_listener2017-06-13

📋Vendor Advisories

1
Cisco
Cisco Elastic Services Controller Authentication Request Processing Arbitrary Command Execution Vulnerability2017-06-07
CVE-2017-6683 (HIGH CVSS 8.8) | A vulnerability in the esc_listener | cvebase.io