Lucene search

K
cveCiscoCVE-2017-6694
HistoryJun 13, 2017 - 6:29 a.m.

CVE-2017-6694

2017-06-1306:29:01
CWE-522
cisco
web.nvd.nist.gov
26
vulnerability
vnfm
logging function
cisco
ultra services platform
authenticated
local attacker
sensitive data
cleartext credentials
cscvd29355
nvd
cve-2017-6694

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0

Percentile

5.1%

A vulnerability in the Virtual Network Function Manager’s (VNFM) logging function of Cisco Ultra Services Platform could allow an authenticated, local attacker to view sensitive data (cleartext credentials) on an affected system. More Information: CSCvd29355. Known Affected Releases: 21.0.v0.65839.

Affected configurations

Nvd
Node
ciscoultra_services_platformMatch21.0.v0.65839
VendorProductVersionCPE
ciscoultra_services_platform21.0.v0.65839cpe:2.3:a:cisco:ultra_services_platform:21.0.v0.65839:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Cisco Ultra Services Platform",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Cisco Ultra Services Platform"
      }
    ]
  }
]

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2017-6694