ID

VAR-201708-1357


CVE

CVE-2017-6767


TITLE

Cisco Application Policy Infrastructure Controller Vulnerabilities related to authorization, permissions, and access control

Trust: 0.8

sources: JVNDB: JVNDB-2017-007075

DESCRIPTION

A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to gain higher privileges than the account is assigned. The attacker will be granted the privileges of the last user to log in, regardless of whether those privileges are higher or lower than what should have been granted. The attacker cannot gain root-level privileges. The vulnerability is due to a limitation with how Role-Based Access Control (RBAC) grants privileges to remotely authenticated users when login occurs via SSH directly to the local management interface of the APIC. An attacker could exploit this vulnerability by authenticating to the targeted device. The attacker's privilege level will be modified to match that of the last user to log in via SSH. An exploit could allow the attacker to gain elevated privileges and perform CLI commands that should be restricted by the attacker's configured role. Cisco Bug IDs: CSCvc34335. Known Affected Releases: 1.0(1e), 1.0(1h), 1.0(1k), 1.0(1n), 1.0(2j), 1.0(2m), 1.0(3f), 1.0(3i), 1.0(3k), 1.0(3n), 1.0(4h), 1.0(4o); 1.1(0.920a), 1.1(1j), 1.1(3f); 1.2 Base, 1.2(2), 1.2(3), 1.2.2; 1.3(1), 1.3(2), 1.3(2f); 2.0 Base, 2.0(1). Vendors have confirmed this vulnerability Bug ID CSCvc34335 It is released as.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. An elevation of privilege vulnerability exists in Cisco APIC

Trust: 2.07

sources: NVD: CVE-2017-6767 // JVNDB: JVNDB-2017-007075 // BID: 100400 // VULHUB: VHN-114970 // VULMON: CVE-2017-6767

AFFECTED PRODUCTS

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.0\(3n\)

Trust: 1.6

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.0\(3k\)

Trust: 1.6

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.2\(3\)

Trust: 1.6

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.0\(2m\)

Trust: 1.6

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.0\(1h\)

Trust: 1.6

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.0\(4h\)

Trust: 1.6

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.1\(0.920a\)

Trust: 1.6

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.0\(1k\)

Trust: 1.6

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.0\(1e\)

Trust: 1.6

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.0\(4o\)

Trust: 1.6

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.1\(1j\)

Trust: 1.0

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.0\(2j\)

Trust: 1.0

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.0\(3i\)

Trust: 1.0

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.2_base

Trust: 1.0

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.3\(2\)

Trust: 1.0

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.3\(2f\)

Trust: 1.0

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.0\(3f\)

Trust: 1.0

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.2\(2\)

Trust: 1.0

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.1\(3f\)

Trust: 1.0

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.2.2

Trust: 1.0

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:2.0\(1\)

Trust: 1.0

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.0\(1n\)

Trust: 1.0

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:1.3\(1\)

Trust: 1.0

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:2.0_base

Trust: 1.0

vendor:ciscomodel:application policy infrastructure controller softwarescope: - version: -

Trust: 0.8

vendor:ciscomodel:application policy infrastructure controller 2.1scope: - version: -

Trust: 0.3

vendor:ciscomodel:application policy infrastructure controller 2.0scope: - version: -

Trust: 0.3

vendor:ciscomodel:application policy infrastructure controllerscope:eqversion:2.0(0.400)

Trust: 0.3

vendor:ciscomodel:application policy infrastructure controller 1.3scope: - version: -

Trust: 0.3

sources: BID: 100400 // JVNDB: JVNDB-2017-007075 // CNNVD: CNNVD-201708-784 // NVD: CVE-2017-6767

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-6767
value: HIGH

Trust: 1.0

NVD: CVE-2017-6767
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201708-784
value: HIGH

Trust: 0.6

VULHUB: VHN-114970
value: MEDIUM

Trust: 0.1

VULMON: CVE-2017-6767
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-6767
severity: MEDIUM
baseScore: 4.6
vectorString: AV:N/AC:H/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: HIGH
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-114970
severity: MEDIUM
baseScore: 4.6
vectorString: AV:N/AC:H/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: HIGH
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-6767
baseSeverity: HIGH
baseScore: 7.1
vectorString: CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: LOW
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.2
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-114970 // VULMON: CVE-2017-6767 // JVNDB: JVNDB-2017-007075 // CNNVD: CNNVD-201708-784 // NVD: CVE-2017-6767

PROBLEMTYPE DATA

problemtype:CWE-269

Trust: 1.1

problemtype:CWE-264

Trust: 0.9

sources: VULHUB: VHN-114970 // JVNDB: JVNDB-2017-007075 // NVD: CVE-2017-6767

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201708-784

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-201708-784

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-007075

PATCH

title:cisco-sa-20170816-apic1url:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170816-apic1

Trust: 0.8

title:Cisco Application Policy Infrastructure Controller Fixes for permission permissions and access control vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=74101

Trust: 0.6

title:Cisco: Cisco Application Policy Infrastructure Controller SSH Privilege Escalation Vulnerabilityurl:https://vulmon.com/vendoradvisory?qidtp=cisco_security_advisories_and_alerts_ciscoproducts&qid=cisco-sa-20170816-apic1

Trust: 0.1

sources: VULMON: CVE-2017-6767 // JVNDB: JVNDB-2017-007075 // CNNVD: CNNVD-201708-784

EXTERNAL IDS

db:NVDid:CVE-2017-6767

Trust: 2.9

db:BIDid:100400

Trust: 2.1

db:SECTRACKid:1039180

Trust: 1.8

db:JVNDBid:JVNDB-2017-007075

Trust: 0.8

db:CNNVDid:CNNVD-201708-784

Trust: 0.7

db:VULHUBid:VHN-114970

Trust: 0.1

db:VULMONid:CVE-2017-6767

Trust: 0.1

sources: VULHUB: VHN-114970 // VULMON: CVE-2017-6767 // BID: 100400 // JVNDB: JVNDB-2017-007075 // CNNVD: CNNVD-201708-784 // NVD: CVE-2017-6767

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20170816-apic1

Trust: 2.2

url:http://www.securityfocus.com/bid/100400

Trust: 1.8

url:http://www.securitytracker.com/id/1039180

Trust: 1.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-6767

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-6767

Trust: 0.8

url:http://www.cisco.com/c/en/us/products/cloud-systems-management/application-policy-infrastructure-controller-apic/index.html

Trust: 0.3

url:http://www.cisco.com/

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/269.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-114970 // VULMON: CVE-2017-6767 // BID: 100400 // JVNDB: JVNDB-2017-007075 // CNNVD: CNNVD-201708-784 // NVD: CVE-2017-6767

CREDITS

Cisco

Trust: 0.3

sources: BID: 100400

SOURCES

db:VULHUBid:VHN-114970
db:VULMONid:CVE-2017-6767
db:BIDid:100400
db:JVNDBid:JVNDB-2017-007075
db:CNNVDid:CNNVD-201708-784
db:NVDid:CVE-2017-6767

LAST UPDATE DATE

2024-11-23T22:26:42.366000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-114970date:2019-10-03T00:00:00
db:VULMONid:CVE-2017-6767date:2019-10-03T00:00:00
db:BIDid:100400date:2017-08-16T00:00:00
db:JVNDBid:JVNDB-2017-007075date:2017-09-11T00:00:00
db:CNNVDid:CNNVD-201708-784date:2019-10-23T00:00:00
db:NVDid:CVE-2017-6767date:2024-11-21T03:30:28.760

SOURCES RELEASE DATE

db:VULHUBid:VHN-114970date:2017-08-17T00:00:00
db:VULMONid:CVE-2017-6767date:2017-08-17T00:00:00
db:BIDid:100400date:2017-08-16T00:00:00
db:JVNDBid:JVNDB-2017-007075date:2017-09-11T00:00:00
db:CNNVDid:CNNVD-201708-784date:2017-08-18T00:00:00
db:NVDid:CVE-2017-6767date:2017-08-17T20:29:00.400