PT-2017-17265 · Cisco+1 · Cisco Ultra Services Framework Uas+1

Published

2017-07-06

·

Updated

2019-10-09

·

CVE-2017-6711

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco Ultra Services Framework UAS versions prior to 5.0.3 and 5.1
Description A vulnerability in the Ultra Automation Service (UAS) could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device. This issue is due to an insecure default configuration of the Apache ZooKeeper service. An attacker could exploit this by accessing the device through the orchestrator network, potentially gaining access to ZooKeeper data nodes (znodes) and influencing the system's high-availability feature.
Recommendations For versions prior to 5.0.3, update to Release 5.0.3 or later. For versions prior to 5.1, update to Release 5.1 or later. As a temporary workaround, consider restricting access to the Apache ZooKeeper service to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6711

Affected Products

Apache Zookeeper
Cisco Ultra Services Framework Uas