Cisco Prime Collaboration Provisioning Tool Information Disclosure Vulnerability

cisco-sa-20170621-pcp3 · Medium · Published · Updated

Data: Cisco advisories · Cisco CSAF · NVD CVEs · NVD CPEs · CISA KEV · EPSS

A vulnerability in the filesystem of the Cisco Prime Collaboration Provisioning tool could allow an authenticated, local attacker to acquire sensitive information. The vulnerability is due to insecure file permissions. A successful exploit could allow the attacker to access sensitive information about the system. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-pcp3

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2017-6705
Cisco Bug IDsCSCvc82973
CVSS ScoreBase 5.5
Base 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:X/RL:X/RC:X

Products with public affected evidence