Vulnslist

find the latest Cisco vulnerabilities

Cisco Prime Network Information Disclosure Vulnerability

cisco-sa-20170705-cpn · Medium · Published · Updated

A vulnerability in the CLI of the Cisco Prime Network Gateway could allow an authenticated, local attacker to retrieve system process information, which could lead to the disclosure of confidential information. The vulnerability is due to a lack of input and validation checking mechanisms in the system. An attacker could exploit this vulnerability by issuing specific, known commands after authenticating locally to the system via the CLI. A successful exploit could allow the attacker to view confidential information that should only be visible to authenticated users. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170705-cpn

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2017-6726
Cisco Bug IDsCSCvd59341
CVSS ScoreBase 5.5
Base 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Prime Network

Related Products

Product CVE Evidence
Cisco Nexus Dashboard CVE-2017-6726 Cisco OpenVuln
Cisco Meraki MS Series Switches CVE-2017-6726 Cisco OpenVuln
Cisco Prime Network CVE-2017-6726 Cisco OpenVuln