CVE-2017-6693: Medium severity cisco elastic services controller major vulnerability
Published Jun 13, 2017
·Updated
A vulnerability in the ConfD server component of Cisco Elastic Services Controllers could allow an authenticated, local attacker to access information stored in the file system of an affected system, aka Unauthorized Directory Access. More Information: CSCvd76286. Known Affected Releases: 2.2(9.76) 2.3(1).
Affected Software
2 affected components
Cisco Elastic Services Controller=2.2\(9.76\)
Cisco Elastic Services Controller=2.3\(1\)
Event History
Jun 13, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-6693?
CVE-2017-6693 is classified as a medium severity vulnerability.
2
How do I fix CVE-2017-6693?
To fix CVE-2017-6693, upgrade to the fixed release version of Cisco Elastic Services Controller.
3
What could an attacker do with CVE-2017-6693?
An attacker could potentially access sensitive information from the file system of an affected system.
4
Is CVE-2017-6693 a remote access vulnerability?
CVE-2017-6693 specifically requires local authentication for exploitation.
5
Which software versions are affected by CVE-2017-6693?
CVE-2017-6693 affects Cisco Elastic Services Controller versions 2.2(9.76) and 2.3(1).