PT-2017-17265 · Cisco+1 · Cisco Ultra Services Framework Uas+1
Publicado
2017-07-06
·
Atualizado
2019-10-09
·
CVE-2017-6711
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Ultra Services Framework UAS versions prior to 5.0.3 and 5.1
Description
A vulnerability in the Ultra Automation Service (UAS) could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device. This issue is due to an insecure default configuration of the Apache ZooKeeper service. An attacker could exploit this by accessing the device through the orchestrator network, potentially gaining access to ZooKeeper data nodes (znodes) and influencing the system's high-availability feature.
Recommendations
For versions prior to 5.0.3, update to Release 5.0.3 or later.
For versions prior to 5.1, update to Release 5.1 or later.
As a temporary workaround, consider restricting access to the Apache ZooKeeper service to minimize the risk of exploitation.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Zookeeper
Cisco Ultra Services Framework Uas