CVE-2017-6710
Summary
| CVE | CVE-2017-6710 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-17 20:29:00 UTC |
| Updated | 2017-08-25 11:04:00 UTC |
| Description | A vulnerability in the Cisco Virtual Network Function (VNF) Element Manager could allow an authenticated, remote attacker to elevate privileges and run commands in the context of the root user on the server. The vulnerability is due to command settings that allow Cisco VNF Element Manager users to specify arbitrary commands that will run as root on the server. An attacker could use this setting to elevate privileges and run commands in the context of the root user on the server. Cisco Bug IDs: CSCvc76670. Known Affected Releases: prior to 5.0.4 and 5.1.4. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Virtual Network Function Element Manager | All | All | All | All |
| Application | Cisco | Virtual Network Function Element Manager | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Virtual Network Function Element Manager Arbitrary Command Execution Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| Cisco Virtual Network Function Element Manager CVE-2017-6710 Remote Command Execution Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.