CVE-2017-3843: Input Validation
A vulnerability in the file download functions for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to download system files that should be restricted. More Information: CSCvc99446. Known Affected Releases: 11.5(0).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Prime Collaboration Assuranceto a version that resolves this vulnerability.Fixed in 11.5(0)Patch CSCvc99446
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3843?
CVE-2017-3843 is classified as a high severity vulnerability that could lead to unauthorized file downloads.
How do I fix CVE-2017-3843?
To fix CVE-2017-3843, you should upgrade to a patched version of Cisco Prime Collaboration Assurance.
Who is affected by CVE-2017-3843?
CVE-2017-3843 affects users of Cisco Prime Collaboration Assurance versions 11.0.0, 11.1.0, and 11.5.0.
What could be the impact of CVE-2017-3843?
The impact of CVE-2017-3843 includes the potential for authenticated attackers to access and download restricted system files.
Is CVE-2017-3843 actively exploited?
There are currently no public reports confirming active exploitation of CVE-2017-3843, but it remains a security risk.