CVE-2017-6696

Severity
5.5MEDIUM
EPSS
0.1%
top 79.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 17

Description

A vulnerability in the file system of Cisco Elastic Services Controllers could allow an authenticated, local attacker to gain access to sensitive user credentials that are stored in an affected system. More Information: CSCvd73677. Known Affected Releases: 2.3(2).

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5cisco_elastic_services_controllerCisco Elastic Services Controller

🔴Vulnerability Details

2
GHSA
GHSA-2vwh-gpg3-5pm3: A vulnerability in the file system of Cisco Elastic Services Controllers could allow an authenticated, local attacker to gain access to sensitive user2022-05-17
CVEList
CVE-2017-6696: A vulnerability in the file system of Cisco Elastic Services Controllers could allow an authenticated, local attacker to gain access to sensitive user2017-06-13

📋Vendor Advisories

1
Cisco
Cisco Elastic Services Controller User Credentials Information Disclosure Vulnerability2017-06-07
CVE-2017-6696 (MEDIUM CVSS 5.5) | A vulnerability in the file system | cvebase.io