cbcvebase.

Cisco Systems Inc Elastic Services Controller vulnerabilities

4 known vulnerabilities affecting cisco_systems_inc/elastic_services_controller.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2017-6776P4MEDIUMCVSS 6.1v2.2(9.76)v2.3(1)2017-08-17
CVE-2017-6776 [MEDIUM] CWE-79 CVE-2017-6776: A vulnerability in the web framework of Cisco Elastic Services Controller (ESC) could allow an unaut A vulnerability in the web framework of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulnerabil
nvd
CVE-2017-6786P4MEDIUMCVSS 6.3v2.2(9.76).2017-08-17
CVE-2017-6786 [MEDIUM] CWE-200 CVE-2017-6786: A vulnerability in Cisco Elastic Services Controller could allow an authenticated, local, unprivileg A vulnerability in Cisco Elastic Services Controller could allow an authenticated, local, unprivileged attacker to access sensitive information, including credentials for system accounts, on an affected system. The vulnerability is due to improper protection of sensitive log files. An attacker could exploit this vulnerability by logging in to an affec
nvd
CVE-2017-6777P4MEDIUMCVSS 4.9v2.3, 2.3(2)2017-08-17
CVE-2017-6777 [MEDIUM] CWE-200 CVE-2017-6777: A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an au A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to acquire sensitive system information. The vulnerability is due to insufficient protection of sensitive files on the system. An attacker could exploit this vulnerability by logging into the ConfD server and executing certa
nvd
CVE-2017-6772P4MEDIUMCVSS 4.3v2.3(2)2017-08-17
CVE-2017-6772 [MEDIUM] CWE-200 CVE-2017-6772: A vulnerability in Cisco Elastic Services Controller (ESC) could allow an authenticated, remote atta A vulnerability in Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to insufficient protection of sensitive data. An attacker could exploit this vulnerability by authenticating to the application and navigating to certain configuration files. An exploit could
nvd
Cisco Systems Inc Elastic Services Controller vulnerabilities | cvebase