PT-2018-8613 · Cisco+1 · Cisco Elastic Services Controller+1

Published

2018-01-18

·

Updated

2020-09-04

·

CVE-2018-0106

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Elastic Services Controller (ESC) (affected versions not specified)
Description: A vulnerability in the ConfD server could allow an unauthenticated, local attacker to access sensitive information on a targeted system due to insufficient security restrictions. An attacker could exploit this by accessing unauthorized information within the ConfD directory and file structure, potentially allowing them to view sensitive information.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-0106

Affected Products

Cisco Elastic Services Controller
Confd