Vulnslist

find the latest Cisco vulnerabilities

Cisco Ultra Services Platform Deployment Configuration Information Disclosure Vulnerability

cisco-sa-20170816-usp · Medium · Published · Updated

A vulnerability in the Elastic Services Controller (ESC) web interface of the Cisco Ultra Services Platform could allow an authenticated, remote attacker to acquire sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker could exploit this vulnerability by sending a GET request to a vulnerable device. An exploit could allow the attacker to view information regarding the Ultra Services Platform deployment. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170816-usp

Cisco advisory · CSAF JSON

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2017-6778
Cisco Bug IDsCSCvd76406
CVSS ScoreBase 4.9
Base 4.9 CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Ultra Services Platform

Related Products

Product CVE Evidence
Cisco Ultra Services Platform CVE-2017-6778 Cisco OpenVuln