First published: Wed Feb 22 2017(Updated: )
A vulnerability in the file download functions for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to download system files that should be restricted. More Information: CSCvc99446. Known Affected Releases: 11.5(0).
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Collaboration Assurance | =11.0.0 | |
Cisco Prime Collaboration Assurance | =11.1.0 | |
Cisco Prime Collaboration Assurance | =11.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3843 is classified as a high severity vulnerability that could lead to unauthorized file downloads.
To fix CVE-2017-3843, you should upgrade to a patched version of Cisco Prime Collaboration Assurance.
CVE-2017-3843 affects users of Cisco Prime Collaboration Assurance versions 11.0.0, 11.1.0, and 11.5.0.
The impact of CVE-2017-3843 includes the potential for authenticated attackers to access and download restricted system files.
There are currently no public reports confirming active exploitation of CVE-2017-3843, but it remains a security risk.