CVE-2017-6689
published 2017-06-13CVE-2017-6689: A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the…
PriorityP348high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.50%
71.3th percentile
A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the admin user, aka an Insecure Default Administrator Credentials Vulnerability. More Information: CSCvc76661. Known Affected Releases: 2.2(9.76).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | elastic_services_controller | — | — |
| cisco | elastic_services_controller | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Elastic Services Controller Insecure Default Administrator Credentials Vulnerability
vendor_cisco·2017-06-07·CVSS 6.3
CVE-2017-6689 [MEDIUM] CWE-255 Cisco Elastic Services Controller Insecure Default Administrator Credentials Vulnerability
Cisco Elastic Services Controller Insecure Default Administrator Credentials Vulnerability
A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the admin user.
The vulnerability is due to the existence of a default, weak, hard-coded password for the admin user of an affected system. An attacker could exploit this vulnerability by logging in to an affected system via Secure Shell (SSH) on TCP port 2024 and using the default password to authenticate to the system as the admin user. A successful exploit could allow the attacker to log in to the affected system as the admin user and perform actions associated with the privileges of the admin user.
There are no workarounds that address this vul
Cisco
Cisco Elastic Services Controller Insecure Default Administrator Credentials Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-6689 Cisco Elastic Services Controller Insecure Default Administrator Credentials Vulnerability
CVE-2017-6689: Cisco Elastic Services Controller Insecure Default Administrator Credentials Vulnerability
A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the admin user. The vulnerability is due to the existence of a default, weak, hard-coded password for the admin user of an affected system. An attacker could exploit this vulnerability by logging in to an affected system via Secure Shell (SSH) on TCP port 2024 and using the default password to authenticate to the system as the admin user. A successful exploit could allow the attacker to log in to the affected system as the admin user and perform actions associated with the privileges of the admin user. There are no
CVSS: 3.0
CWE: CWE-25
GHSA
GHSA-g6w4-9j8g-23j4: A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system a
ghsa_unreviewed·2022-05-13
CVE-2017-6689 [HIGH] CWE-1188 GHSA-g6w4-9j8g-23j4: A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system a
A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the admin user, aka an Insecure Default Administrator Credentials Vulnerability. More Information: CSCvc76661. Known Affected Releases: 2.2(9.76).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-06-13
Published