CVE-2017-6691: Infoleak
Published Jun 13, 2017
·Updated
A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to access sensitive information on an affected system. More Information: CSCvd29403. Known Affected Releases: 2.3(2).
Affected Software
1 affected component
Cisco Elastic Services Controller=2.3\(2\)
Event History
Jun 13, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-6691?
CVE-2017-6691 is rated as a medium severity vulnerability.
2
How do I fix CVE-2017-6691?
To remediate CVE-2017-6691, upgrade to a patched version of Cisco Elastic Services Controller beyond 2.3(2).
3
What systems are affected by CVE-2017-6691?
CVE-2017-6691 specifically affects the Cisco Elastic Services Controller version 2.3(2).
4
Who can exploit CVE-2017-6691?
An authenticated, remote attacker can exploit CVE-2017-6691 to access sensitive information.
5
Is there a workaround for CVE-2017-6691?
There are currently no documented workarounds for CVE-2017-6691 apart from upgrading the affected software.