CVE-2017-6759
A vulnerability in the UpgradeManager of the Cisco Prime Collaboration Provisioning Tool 12.1 could allow an authenticated, remote attacker to write arbitrary files as root on the system.
Does this matter?
Lower severity and a low EPSS score (1.54%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability in the UpgradeManager of the Cisco Prime Collaboration Provisioning Tool 12.1 could allow an authenticated, remote attacker to write arbitrary files as root on the system. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by triggering the upgrade package installation functionality. Cisco Bug IDs: CSCvc90304.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.54% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- cisco/prime collaboration provisioning
- Source
- psirt@cisco.com
References
- http://www.securitytracker.com/id/1039062Third Party Advisory, VDB Entry
- https://quickview.cloudapps.cisco.com/quickview/bug/CSCvc90304Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170802-pcptVendor Advisory
- http://www.securitytracker.com/id/1039062Third Party Advisory, VDB Entry
- https://quickview.cloudapps.cisco.com/quickview/bug/CSCvc90304Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170802-pcptVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.