PT-2017-17265 · Cisco+1 · Cisco Ultra Services Framework Uas+1

Publicado

2017-07-06

·

Atualizado

2019-10-09

·

CVE-2017-6711

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco Ultra Services Framework UAS versions prior to 5.0.3 and 5.1
Description A vulnerability in the Ultra Automation Service (UAS) could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device. This issue is due to an insecure default configuration of the Apache ZooKeeper service. An attacker could exploit this by accessing the device through the orchestrator network, potentially gaining access to ZooKeeper data nodes (znodes) and influencing the system's high-availability feature.
Recommendations For versions prior to 5.0.3, update to Release 5.0.3 or later. For versions prior to 5.1, update to Release 5.1 or later. As a temporary workaround, consider restricting access to the Apache ZooKeeper service to minimize the risk of exploitation.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-6711

Produtos afetados

Apache Zookeeper
Cisco Ultra Services Framework Uas