CVE-2017-6684
published 2017-06-13CVE-2017-6684: A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux admin user…
PriorityP351high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.28%
81.1th percentile
A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux admin user, aka an Insecure Default Credentials Vulnerability. More Information: CSCvc76651. Known Affected Releases: 21.0.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | elastic_services_controller | — | — |
| cisco | elastic_services_controller | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jgf9-3c8r-rc2p: A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux admin
ghsa_unreviewed·2022-05-13
CVE-2017-6684 [HIGH] CWE-1188 GHSA-jgf9-3c8r-rc2p: A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux admin
A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux admin user, aka an Insecure Default Credentials Vulnerability. More Information: CSCvc76651. Known Affected Releases: 21.0.0.
Cisco
Cisco Elastic Services Controller Insecure Default Credentials Vulnerability
vendor_cisco·2017-06-07·CVSS 6.3
CVE-2017-6684 [MEDIUM] CWE-255 Cisco Elastic Services Controller Insecure Default Credentials Vulnerability
Cisco Elastic Services Controller Insecure Default Credentials Vulnerability
A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux admin user.
The vulnerability is due to the existence of a default, weak, hard-coded password for the Linux admin user of an affected system. A successful exploit could allow the attacker to log in to the affected system as the Linux admin user and perform actions associated with the privileges of the admin user.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-esc3
Cisco
Cisco Elastic Services Controller Insecure Default Credentials Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-6684 Cisco Elastic Services Controller Insecure Default Credentials Vulnerability
CVE-2017-6684: Cisco Elastic Services Controller Insecure Default Credentials Vulnerability
A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux admin user. The vulnerability is due to the existence of a default, weak, hard-coded password for the Linux admin user of an affected system. A successful exploit could allow the attacker to log in to the affected system as the Linux admin user and perform actions associated with the privileges of the admin user. There are no
CVSS: 3.0
CWE: CWE-255, CWE-255
Bug IDs: CSCvc76651
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-06-13
Published