PT-2017-17248 · Cisco · Cisco Ultra Services Platform
Published
2017-06-13
·
Updated
2019-10-03
·
CVE-2017-6694
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Ultra Services Platform version 21.0.v0.65839
Description
A vulnerability in the Virtual Network Function Manager's (VNFM) logging function could allow an authenticated, local attacker to view sensitive data, including cleartext credentials, on an affected system.
Recommendations
For version 21.0.v0.65839, consider restricting access to the logging function to minimize the risk of exploitation until a fix is available. As a temporary workaround, limit local access to the system to reduce the potential for attackers to view sensitive data.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ultra Services Platform