First published: Tue Jun 13 2017(Updated: )
A vulnerability in the ConfD server component of Cisco Elastic Services Controllers could allow an authenticated, local attacker to access information stored in the file system of an affected system, aka Unauthorized Directory Access. More Information: CSCvd76286. Known Affected Releases: 2.2(9.76) 2.3(1).
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Elastic Services Controller | =2.2\(9.76\) | |
Cisco Elastic Services Controller | =2.3\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6693 is classified as a medium severity vulnerability.
To fix CVE-2017-6693, upgrade to the fixed release version of Cisco Elastic Services Controller.
An attacker could potentially access sensitive information from the file system of an affected system.
CVE-2017-6693 specifically requires local authentication for exploitation.
CVE-2017-6693 affects Cisco Elastic Services Controller versions 2.2(9.76) and 2.3(1).