6.5
CVSSv3

CVE-2017-6704

Published: 04/07/2017 Updated: 07/07/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allow an authenticated, remote malicious user to perform arbitrary file downloads that could allow the malicious user to read files from the underlying filesystem. More Information: CSCvc90335. Known Affected Releases: 12.1.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco prime collaboration provisioning 12.1

Vendor Advisories

A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allow an authenticated, remote attacker to perform arbitrary file downloads that could allow the attacker to read files from the underlying filesystem The vulnerability is due to insufficient input validation An exploit could allow the attacker to dow ...