CVE-2017-6792: Input Validation
A vulnerability in the batch provisioning feature in Cisco Prime Collaboration Provisioning Tool could allow an authenticated, remote attacker to overwrite system files as root. The vulnerability is due to lack of input validation of the parameters in BatchFileName and Directory. An attacker could exploit this vulnerability by manipulating the parameters of the batch action file function. Cisco Bug IDs: CSCvd61766.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6792?
CVE-2017-6792 has been assigned a high severity level due to its potential for unauthorized file overwriting by remote attackers.
How do I fix CVE-2017-6792?
To fix CVE-2017-6792, upgrade to the latest version of Cisco Prime Collaboration Provisioning that addresses this vulnerability.
What is the impact of CVE-2017-6792?
The impact of CVE-2017-6792 includes the possibility of remote attackers gaining root access to overwrite system files.
Who is affected by CVE-2017-6792?
CVE-2017-6792 affects users of Cisco Prime Collaboration Provisioning Tool who utilize the batch provisioning feature.
Is CVE-2017-6792 exploitable remotely?
Yes, CVE-2017-6792 is exploitable remotely by authenticated attackers.