PT-2017-17315 · Cisco · Cisco Policy Suite

Published

2017-08-17

·

Updated

2019-10-03

·

CVE-2017-6781

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Cisco Policy Suite (CPS) Software for CPS appliances versions 9.0.0 through 12.0.0
Description A vulnerability in the management of shell user accounts could allow an authenticated, local attacker to gain elevated privileges on an affected system. The issue is due to incorrect role-based access control (RBAC) for shell user accounts. An attacker could exploit this by authenticating to an affected appliance and providing crafted user input via the Command Line Interface (CLI). A successful exploit could allow the attacker to acquire a higher privilege level than should have been granted.
Recommendations For versions 9.0.0 through 12.0.0, update to a version that includes the fix for Cisco Bug ID CSCve37724 to resolve the issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6781

Affected Products

Cisco Policy Suite