Vulnslist

find the latest Cisco vulnerabilities

Cisco Elastic Services Controller Configuration Files Information Disclosure Vulnerability

cisco-sa-20170816-esc1 · Medium · Published · Updated

A vulnerability in Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to insufficient protection of sensitive data. An attacker could exploit this vulnerability by authenticating to the application and navigating to certain configuration files. An exploit could allow the attacker to view sensitive system configuration files. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170816-esc1

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2017-6772
Cisco Bug IDsCSCvd29408
CVSS ScoreBase 4.3
Base 4.3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Elastic Services Controller

Related Products

Product CVE Evidence
Cisco RV Series Routers CVE-2017-6772 Cisco OpenVuln
Cisco Nexus Dashboard CVE-2017-6772 Cisco OpenVuln
Cisco Elastic Services Controller CVE-2017-6772 Cisco OpenVuln