First published: Wed Feb 22 2017(Updated: )
A vulnerability in exporting functions of the user interface for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to view file directory listings and download files. Affected Products: Cisco Prime Collaboration Assurance software versions 11.0, 11.1, and 11.5 are vulnerable. Cisco Prime Collaboration Assurance software versions prior to 11.0 are not vulnerable. More Information: CSCvc86238. Known Affected Releases: 11.5(0).
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Collaboration Assurance | =11.0.0 | |
Cisco Prime Collaboration Assurance | =11.1.0 | |
Cisco Prime Collaboration Assurance | =11.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3844 is considered a high severity vulnerability due to the potential for remote authenticated attackers to access sensitive files.
To mitigate CVE-2017-3844, it is recommended to upgrade to a fixed version of Cisco Prime Collaboration Assurance beyond the affected versions 11.0, 11.1, and 11.5.
The products affected by CVE-2017-3844 include Cisco Prime Collaboration Assurance software versions 11.0, 11.1, and 11.5.
Yes, CVE-2017-3844 can be exploited by an authenticated remote attacker to access file directory listings.
Yes, an attacker must be authenticated to exploit CVE-2017-3844 and gain access to sensitive files.