CVE-2017-6688
published 2017-06-13CVE-2017-6688: A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux root user, aka…
PriorityP353high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.28%
81.1th percentile
A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux root user, aka an Insecure Default Password Vulnerability. More Information: CSCvc76631. Known Affected Releases: 2.2(9.76).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | elastic_services_controller | — | — |
| cisco | elastic_services_controller | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-29px-fjqx-xh4f: A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux root
ghsa_unreviewed·2022-05-13
CVE-2017-6688 [HIGH] CWE-1188 GHSA-29px-fjqx-xh4f: A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux root
A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux root user, aka an Insecure Default Password Vulnerability. More Information: CSCvc76631. Known Affected Releases: 2.2(9.76).
Cisco
Cisco Elastic Services Controller Insecure Default Password Vulnerability
vendor_cisco·2017-06-07·CVSS 6.3
CVE-2017-6688 [MEDIUM] CWE-255 Cisco Elastic Services Controller Insecure Default Password Vulnerability
Cisco Elastic Services Controller Insecure Default Password Vulnerability
A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux root user.
The vulnerability is due to the existence of a default, weak, hard-coded password for the Linux root user of an affected system. A successful exploit could allow the attacker to log in to the affected system as the Linux root user and perform actions associated with the privileges of the root user.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-esc4
Cisco
Cisco Elastic Services Controller Insecure Default Password Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-6688 Cisco Elastic Services Controller Insecure Default Password Vulnerability
CVE-2017-6688: Cisco Elastic Services Controller Insecure Default Password Vulnerability
A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux root user. The vulnerability is due to the existence of a default, weak, hard-coded password for the Linux root user of an affected system. A successful exploit could allow the attacker to log in to the affected system as the Linux root user and perform actions associated with the privileges of the root user. There are no
CVSS: 3.0
CWE: CWE-255, CWE-255
Bug IDs: CSCvc76631
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-06-13
Published