PT-2017-17258 · Cisco · Cisco Prime Collaboration Provisioning
Publicado
2017-07-04
·
Atualizado
2017-07-07
·
CVE-2017-6704
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Prime Collaboration Provisioning tool version 12.1
Description
A vulnerability in the web application could allow an authenticated, remote attacker to perform arbitrary file downloads, potentially allowing the attacker to read files from the underlying filesystem.
Recommendations
For version 12.1, update to a version that fixes the issue, as the current version allows arbitrary file downloads that could compromise the system's security.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Prime Collaboration Provisioning