CVE-2017-6759 - CERT CVE
ID CVE-2017-6759
Sažetak A vulnerability in the UpgradeManager of the Cisco Prime Collaboration Provisioning Tool 12.1 could allow an authenticated, remote attacker to write arbitrary files as root on the system. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by triggering the upgrade package installation functionality. Cisco Bug IDs: CSCvc90304.
Reference
CVSS
Base: 6.8
Impact: 6.9
Exploitability:8.0
Pristup
VektorSloženostAutentikacija
NETWORK LOW SINGLE
Impact
PovjerljivostCjelovitostDostupnost
NONE COMPLETE NONE
CVSS vektor AV:N/AC:L/Au:S/C:N/I:C/A:N
Zadnje važnije ažuriranje 09-10-2019 - 23:29
Objavljeno 07-08-2017 - 06:29