PT-2017-17248 · Cisco · Cisco Ultra Services Platform

Publicado

2017-06-13

·

Atualizado

2019-10-03

·

CVE-2017-6694

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Ultra Services Platform version 21.0.v0.65839
Description A vulnerability in the Virtual Network Function Manager's (VNFM) logging function could allow an authenticated, local attacker to view sensitive data, including cleartext credentials, on an affected system.
Recommendations For version 21.0.v0.65839, consider restricting access to the logging function to minimize the risk of exploitation until a fix is available. As a temporary workaround, limit local access to the system to reduce the potential for attackers to view sensitive data.

Correção

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-6694

Produtos afetados

Cisco Ultra Services Platform