CVE-2017-6714
Last modified
CVE-2017-6714 is a vulnerability of currently unknown severity. A vulnerability in the AutoIT service of Cisco Ultra Services Framework Staging Server could allow an unauthenticated, remote attacker to execute arbitrary shell commands as the Linux root user. The vulnerability is due to improper shell invocations. EPSS estimates a 4.20% chance of exploitation in the next 30 days.
Description
A vulnerability in the AutoIT service of Cisco Ultra Services Framework Staging Server could allow an unauthenticated, remote attacker to execute arbitrary shell commands as the Linux root user. The vulnerability is due to improper shell invocations. An attacker could exploit this vulnerability by crafting CLI command inputs to execute Linux shell commands as the root user. This vulnerability affects all releases of Cisco Ultra Services Framework Staging Server prior to Releases 5.0.3 and 5.1. Cisco Bug IDs: CSCvc76673.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ultra Services Framework Staging Server | <= 5.0.2 |
References
- http://www.securityfocus.com/bid/99436Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/99436Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-6714?
How severe is CVE-2017-6714?
How do I fix CVE-2017-6714?
Are you affected by CVE-2017-6714?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
