Vulnslist

find the latest Cisco vulnerabilities

Cisco Elastic Services Controller Arbitrary Command Execution Vulnerability

cisco-sa-20170705-esc1 · High · Published · Updated

A vulnerability in certain commands of Cisco Elastic Services Controller could allow an authenticated, remote attacker to elevate privileges to root and run dangerous commands on the server. The vulnerability occurs because a "tomcat" user on the system can run certain shell commands, allowing the user to overwrite any file on the filesystem and elevate privileges to root. An exploit could allow an authenticated, remote attacker to elevate privileges and run dangerous commands on the server. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.  This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170705-esc1

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2017-6712
Cisco Bug IDsCSCvc76634
CVSS ScoreBase 8.8
Base 8.8 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco Elastic Services Controller

Related Products

Product CVE Evidence
Cisco RV Series Routers CVE-2017-6712 Cisco OpenVuln
Cisco Nexus Dashboard CVE-2017-6712 Cisco OpenVuln
Cisco Elastic Services Controller CVE-2017-6712 Cisco OpenVuln