CVE-2017-3844: Input Validation
A vulnerability in exporting functions of the user interface for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to view file directory listings and download files. Affected Products: Cisco Prime Collaboration Assurance software versions 11.0, 11.1, and 11.5 are vulnerable. Cisco Prime Collaboration Assurance software versions prior to 11.0 are not vulnerable. More Information: CSCvc86238. Known Affected Releases: 11.5(0).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Prime Collaboration Assuranceto a version that resolves this vulnerability.Fixed in 11.5(0)Patch CSCvc86238
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3844?
CVE-2017-3844 is considered a high severity vulnerability due to the potential for remote authenticated attackers to access sensitive files.
How do I fix CVE-2017-3844?
To mitigate CVE-2017-3844, it is recommended to upgrade to a fixed version of Cisco Prime Collaboration Assurance beyond the affected versions 11.0, 11.1, and 11.5.
What products are affected by CVE-2017-3844?
The products affected by CVE-2017-3844 include Cisco Prime Collaboration Assurance software versions 11.0, 11.1, and 11.5.
Can CVE-2017-3844 be exploited remotely?
Yes, CVE-2017-3844 can be exploited by an authenticated remote attacker to access file directory listings.
Is authentication required to exploit CVE-2017-3844?
Yes, an attacker must be authenticated to exploit CVE-2017-3844 and gain access to sensitive files.