First published: Tue Jun 13 2017(Updated: )
A vulnerability in the file system of Cisco Elastic Services Controllers could allow an authenticated, local attacker to gain access to sensitive user credentials that are stored in an affected system. More Information: CSCvd73677. Known Affected Releases: 2.3(2).
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Elastic Services Controller | =2.3\(2\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6696 has a high severity rating due to the potential for sensitive user credentials to be accessed by an authenticated local attacker.
To fix CVE-2017-6696, upgrade to a version of Cisco Elastic Services Controller that is not affected by this vulnerability.
CVE-2017-6696 specifically affects Cisco Elastic Services Controller version 2.3(2).
CVE-2017-6696 can be exploited by an authenticated local attacker who has access to the system.
CVE-2017-6696 may expose sensitive user credentials stored in the affected system.