Vulnerability Name: | CVE-2017-6774 (CCN-130538) | ||||||||||||
Assigned: | 2017-08-16 | ||||||||||||
Published: | 2017-08-16 | ||||||||||||
Updated: | 2019-10-03 | ||||||||||||
Summary: | A vulnerability in Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, remote attacker to overwrite or modify sensitive system files. The vulnerability is due to the inclusion of sensitive system files within specific FTP subdirectories. An attacker could exploit this vulnerability by overwriting sensitive configuration files through FTP. An exploit could allow the attacker to overwrite configuration files on an affected system. Cisco Bug IDs: CSCvd47739. Known Affected Releases: 21.0.v0.65839. | ||||||||||||
CVSS v3 Severity: | 5.0 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N) 4.4 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N/E:U/RL:O/RC:C)
3.6 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-552 | ||||||||||||
Vulnerability Consequences: | File Manipulation | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-6774 Source: BID Type: Third Party Advisory, VDB Entry 100386 Source: CCN Type: BID-100386 Cisco StarOS for ASR 5000 Series Routers CVE-2017-6774 Arbitrary File Write Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1039182 Source: XF Type: UNKNOWN cisco-cve20176774-file-overwrite(130538) Source: CCN Type: Cisco Security Advisory cisco-sa-20170816-staros2 Cisco StarOS for ASR 5000 Series Routers FTP Configuration File Modification Vulnerability Source: CISCO Type: Vendor Advisory 20170816 Cisco StarOS for ASR 5000 Series Routers FTP Configuration File Modification Vulnerability | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |