CVE-2017-6772: Infoleak
A vulnerability in Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to insufficient protection of sensitive data. An attacker could exploit this vulnerability by authenticating to the application and navigating to certain configuration files. An exploit could allow the attacker to view sensitive system configuration files. Cisco Bug IDs: CSCvd29408. Known Affected Releases: 2.3(2).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6772?
The severity of CVE-2017-6772 is considered medium due to its potential for sensitive data exposure.
How do I fix CVE-2017-6772?
To fix CVE-2017-6772, ensure to apply the latest security updates and patches provided by Cisco for the Elastic Services Controller.
Who is affected by CVE-2017-6772?
CVE-2017-6772 affects users of Cisco Elastic Services Controller version 2.3(2).
What kind of data can be exposed by CVE-2017-6772?
CVE-2017-6772 can lead to the exposure of sensitive information stored within the affected Cisco application.
Is authentication required to exploit CVE-2017-6772?
Yes, an attacker needs to be authenticated to exploit CVE-2017-6772 and view sensitive information.