René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

171 lines
6.7 KiB
JSON

{
"id": "CVE-2017-6621",
"sourceIdentifier": "ykramarz@cisco.com",
"published": "2017-05-18T19:29:00.203",
"lastModified": "2017-07-08T01:29:13.663",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the web interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to insufficient protection of sensitive data when responding to an HTTP request on the web interface. An attacker could exploit the vulnerability by sending a crafted HTTP request to the application to access specific system files. An exploit could allow the attacker to obtain sensitive information about the application which could include user credentials. This vulnerability affects Cisco Prime Collaboration Provisioning Software Releases 10.6 through 11.5. Cisco Bug IDs: CSCvc99626."
},
{
"lang": "es",
"value": "Una vulnerabilidad en la interfaz web de Prime Collaboration Provisioning de Cisco podr\u00eda permitir a un atacante no autenticado remoto acceder a datos confidenciales. El atacante podr\u00eda usar esta informaci\u00f3n para conducir ataques de reconocimiento adicionales. La vulnerabilidad es debido a una protecci\u00f3n insuficiente de los datos confidenciales cuando se responde a una petici\u00f3n HTTP en la interfaz web. Un atacante podr\u00eda explotar la vulnerabilidad mediante el env\u00edo de una petici\u00f3n HTTP dise\u00f1ada a la aplicaci\u00f3n para acceder a archivos espec\u00edficos del sistema. Una vulnerabilidad podr\u00eda permitirle al atacante obtener informaci\u00f3n confidencial sobre la aplicaci\u00f3n que podr\u00eda incluir las credenciales del usuario. Esta vulnerabilidad afecta a Prime Collaboration Provisioning versiones de software desde 10.6 hasta 11.5 de Cisco. IDs de Bug de Cisco: CSCvc99626."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
},
{
"source": "ykramarz@cisco.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:prime_collaboration_provisioning:9.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "23FBBA67-3E61-4C29-AE29-DA9AC85B130E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:prime_collaboration_provisioning:9.5.0:*:*:*:*:*:*:*",
"matchCriteriaId": "ADD5C349-0CCD-4182-8B41-CB199868A318"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:prime_collaboration_provisioning:10.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "A8B93578-B8CF-4977-B2D6-3F2420391008"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:prime_collaboration_provisioning:10.5.0:*:*:*:*:*:*:*",
"matchCriteriaId": "08D10D0F-159A-4C2A-9ECE-4C55ADE37298"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:prime_collaboration_provisioning:10.5.1:*:*:*:*:*:*:*",
"matchCriteriaId": "9D2B13F1-A983-446D-8698-B562801B320B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:prime_collaboration_provisioning:10.6.0:*:*:*:*:*:*:*",
"matchCriteriaId": "00D29AB4-BF27-4366-9CC1-060B8C97067A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:prime_collaboration_provisioning:10.6.2:*:*:*:*:*:*:*",
"matchCriteriaId": "AF0F423A-8552-4406-8E42-3C417AEB4A0B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:prime_collaboration_provisioning:11.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "F05F7FBB-870A-4978-9F6F-E896472E53AA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:prime_collaboration_provisioning:11.1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "8DF611EA-218D-4231-A7AA-1F795132F90E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:prime_collaboration_provisioning:11.5.0:*:*:*:*:*:*:*",
"matchCriteriaId": "31DC57C2-8870-4663-830F-C6209F47DF06"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/bid/98522",
"source": "ykramarz@cisco.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "http://www.securitytracker.com/id/1038508",
"source": "ykramarz@cisco.com"
},
{
"url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170517-pcp2",
"source": "ykramarz@cisco.com",
"tags": [
"VDB Entry"
]
}
]
}