CVE-2017-6689

CWE-1188CWE-2554 documents4 sources
Severity
8.8HIGH
EPSS
0.8%
top 26.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 13

Description

A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the admin user, aka an Insecure Default Administrator Credentials Vulnerability. More Information: CSCvc76661. Known Affected Releases: 2.2(9.76).

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5cisco_elastic_services_controllerCisco Elastic Services Controller

🔴Vulnerability Details

2
GHSA
GHSA-g6w4-9j8g-23j4: A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system a2022-05-13
CVEList
CVE-2017-6689: A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system a2017-06-13

📋Vendor Advisories

1
Cisco
Cisco Elastic Services Controller Insecure Default Administrator Credentials Vulnerability2017-06-07
CVE-2017-6689 (HIGH CVSS 8.8) | A vulnerability in the ConfD CLI of | cvebase.io