CVE-2017-6647 (CNNVD-201705-901)
中文标题:
Cisco Remote Expert Manager Software 信息泄露漏洞
英文标题:
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an u...
漏洞描述
中文描述:
Cisco Remote Expert Manager Software是美国思科(Cisco)公司的的一款远程管理软件。该软件远程屏幕共享、屏幕注释和会话记录等协作功能。 Cisco Remote Expert Manager Software 11.0.0版本中的Web界面存在信息泄露漏洞,该漏洞源于程序没有充分的保护敏感信息。远程攻击者可通过向受影响系统上的软件的Web界面发送特制的HTTP请求利用该漏洞访问受影响系统上敏感Temporary File信息。
英文描述:
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive Temporary File information on an affected system. The vulnerability exists because the affected software does not sufficiently protect sensitive data when responding to HTTP requests that are sent to the web interface of the software. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web interface of the software on an affected system. A successful exploit could allow the attacker to access sensitive information about the software. The attacker could use this information to conduct additional reconnaissance attacks. Cisco Bug IDs: CSCvc52875.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| cisco | remote_expert_manager | 11.0.0 | - | - |
cpe:2.3:a:cisco:remote_expert_manager:11.0.0:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2017-6647 |
2025-11-11 15:19:31 | 2025-11-11 07:34:51 |
| NVD | nvd_CVE-2017-6647 |
2025-11-11 14:55:28 | 2025-11-11 07:43:28 |
| CNNVD | cnnvd_CNNVD-201705-901 |
2025-11-11 15:09:49 | 2025-11-11 07:53:03 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 信息泄露
- cnnvd_id: 未提取 -> CNNVD-201705-901
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 5.3
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 0 -> 1
- data_sources: ['cve'] -> ['cve', 'nvd']