ID

VAR-201708-1349


CVE

CVE-2017-6759


TITLE

Cisco Prime Collaboration Provisioning Tool Input validation vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2017-006839

DESCRIPTION

A vulnerability in the UpgradeManager of the Cisco Prime Collaboration Provisioning Tool 12.1 could allow an authenticated, remote attacker to write arbitrary files as root on the system. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by triggering the upgrade package installation functionality. Cisco Bug IDs: CSCvc90304. Vendors have confirmed this vulnerability Bug ID CSCvc90304 It is released as.Information may be tampered with. This may aid in further attacks. The tool provides IP communications services capabilities for IP telephony, voice mail, and unified communications environments. UpgradeManager is one of the upgrade managers

Trust: 1.98

sources: NVD: CVE-2017-6759 // JVNDB: JVNDB-2017-006839 // BID: 100254 // VULHUB: VHN-114962

AFFECTED PRODUCTS

vendor:ciscomodel:prime collaboration provisioningscope:eqversion:12.1

Trust: 2.7

vendor:ciscomodel:prime collaboration provisioningscope:neversion:12.2(0.12201)

Trust: 0.3

sources: BID: 100254 // JVNDB: JVNDB-2017-006839 // CNNVD: CNNVD-201708-159 // NVD: CVE-2017-6759

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-6759
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-6759
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201708-159
value: MEDIUM

Trust: 0.6

VULHUB: VHN-114962
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-6759
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:C/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-114962
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:C/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-6759
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-114962 // JVNDB: JVNDB-2017-006839 // CNNVD: CNNVD-201708-159 // NVD: CVE-2017-6759

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-114962 // JVNDB: JVNDB-2017-006839 // NVD: CVE-2017-6759

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201708-159

TYPE

input validation error

Trust: 0.6

sources: CNNVD: CNNVD-201708-159

CONFIGURATIONS

[
  {
    "CVE_data_version": "4.0",
    "nodes": [
      {
        "operator": "OR",
        "cpe_match": [
          {
            "vulnerable": true,
            "cpe22Uri": "cpe:/a:cisco:prime_collaboration_provisioning"
          }
        ]
      }
    ]
  }
]

sources: JVNDB: JVNDB-2017-006839

PATCH

title:CSCvc90304 - Cisco Prime Collaboration Provisioning Tool UpgradeManager File Write Vulnerabilityurl:https://quickview.cloudapps.cisco.com/quickview/bug/CSCvc90304

Trust: 0.8

title:cisco-sa-20170802-pcpturl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170802-pcpt

Trust: 0.8

title:Cisco Prime Collaboration Provisioning Tool UpgradeManager Enter the fix for the verification vulnerabilityurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=74826

Trust: 0.6

sources: JVNDB: JVNDB-2017-006839 // CNNVD: CNNVD-201708-159

EXTERNAL IDS

db:NVDid:CVE-2017-6759

Trust: 2.8

db:SECTRACKid:1039062

Trust: 1.7

db:JVNDBid:JVNDB-2017-006839

Trust: 0.8

db:CNNVDid:CNNVD-201708-159

Trust: 0.7

db:BIDid:100254

Trust: 0.4

db:VULHUBid:VHN-114962

Trust: 0.1

sources: VULHUB: VHN-114962 // BID: 100254 // JVNDB: JVNDB-2017-006839 // CNNVD: CNNVD-201708-159 // NVD: CVE-2017-6759

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20170802-pcpt

Trust: 2.0

url:https://quickview.cloudapps.cisco.com/quickview/bug/cscvc90304

Trust: 1.7

url:http://www.securitytracker.com/id/1039062

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-6759

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-6759

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-114962 // BID: 100254 // JVNDB: JVNDB-2017-006839 // CNNVD: CNNVD-201708-159 // NVD: CVE-2017-6759

CREDITS

Cisco.

Trust: 0.3

sources: BID: 100254

SOURCES

db:VULHUBid:VHN-114962
db:BIDid:100254
db:JVNDBid:JVNDB-2017-006839
db:CNNVDid:CNNVD-201708-159
db:NVDid:CVE-2017-6759

LAST UPDATE DATE

2024-11-23T23:05:20.116000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-114962date:2019-10-09T00:00:00
db:BIDid:100254date:2017-08-02T00:00:00
db:JVNDBid:JVNDB-2017-006839date:2017-09-05T00:00:00
db:CNNVDid:CNNVD-201708-159date:2019-10-17T00:00:00
db:NVDid:CVE-2017-6759date:2024-11-21T03:30:27.860

SOURCES RELEASE DATE

db:VULHUBid:VHN-114962date:2017-08-07T00:00:00
db:BIDid:100254date:2017-08-02T00:00:00
db:JVNDBid:JVNDB-2017-006839date:2017-09-05T00:00:00
db:CNNVDid:CNNVD-201708-159date:2017-08-02T00:00:00
db:NVDid:CVE-2017-6759date:2017-08-07T06:29:00.543