CVE-2017-3817: Medium severity cisco Unified Computing System Director vulnerability
A vulnerability in the role-based resource checking functionality of Cisco Unified Computing System (UCS) Director could allow an authenticated, remote attacker to view unauthorized information for any virtual machine in a UCS domain. More Information: CSCvc32434. Known Affected Releases: 5.5(0.1) 6.0(0.0).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco UCS Directorto a version that resolves this vulnerability.Fixed in 5.5(0.1) - Upgrade
Upgrade
Cisco UCS Directorto a version that resolves this vulnerability.Fixed in 6.0(0.0) - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CSCvc32434
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3817?
The severity of CVE-2017-3817 is classified as Medium.
How do I fix CVE-2017-3817?
To fix CVE-2017-3817, upgrade Cisco Unified Computing System Director to a patched version, such as 5.5.0.2 or 6.0.1.0.
Who is impacted by CVE-2017-3817?
CVE-2017-3817 impacts organizations using Cisco Unified Computing System Director versions 5.5.0.1 and 6.0.0.0.
What type of attack does CVE-2017-3817 involve?
CVE-2017-3817 involves an authenticated, remote attack that enables unauthorized information access.
What information could be exposed due to CVE-2017-3817?
CVE-2017-3817 could allow an attacker to view unauthorized information about any virtual machine in a UCS domain.