Vulnerability Description
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker to delete any file from an affected system. The vulnerability exists because the affected software does not perform proper input validation of HTTP requests and fails to apply role-based access controls (RBACs) to requested HTTP URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request that uses directory traversal techniques to submit a path to a desired file location on an affected system. A successful exploit could allow the attacker to delete any file from the system. Cisco Bug IDs: CSCvc99618.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Prime Collaboration Provisioning | 9.0.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/98530Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038515
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
- http://www.securityfocus.com/bid/98530Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038515
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
FAQ
What is CVE-2017-6637?
CVE-2017-6637 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker to delete any file from an affected system...
How severe is CVE-2017-6637?
CVE-2017-6637 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-6637?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Prime Collaboration Provisioning.