CVE-2017-6710 (CNNVD-201708-718)
中文标题:
Cisco Virtual Network Function Element Manager 安全漏洞
英文标题:
A vulnerability in the Cisco Virtual Network Function (VNF) Element Manager could allow an authentic...
漏洞描述
中文描述:
Cisco Virtual Network Function (VNF) Element Manager是美国思科(Cisco)公司的一款VNF(虚拟网络功能)的元素管理器。 Cisco VNF Element Manager 5.0.4之前的版本和5.1.4之前的版本中存在任意命令执行漏洞。远程攻击者可利用该漏洞将权限提升至root,并以root权限执行命令。
英文描述:
A vulnerability in the Cisco Virtual Network Function (VNF) Element Manager could allow an authenticated, remote attacker to elevate privileges and run commands in the context of the root user on the server. The vulnerability is due to command settings that allow Cisco VNF Element Manager users to specify arbitrary commands that will run as root on the server. An attacker could use this setting to elevate privileges and run commands in the context of the root user on the server. Cisco Bug IDs: CSCvc76670. Known Affected Releases: prior to 5.0.4 and 5.1.4.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco Systems, Inc. | Virtual Network Function (VNF) Element Manager | prior to 5.0.4 and 5.1.4 | - | - |
cpe:2.3:a:cisco_systems,_inc.:virtual_network_function_(vnf)_element_manager:prior_to_5.0.4_and_5.1.4:*:*:*:*:*:*:*
|
| cisco | virtual_network_function_element_manager | * | - | - |
cpe:2.3:a:cisco:virtual_network_function_element_manager:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2017-6710 |
2025-11-11 15:19:31 | 2025-11-11 07:34:51 |
| NVD | nvd_CVE-2017-6710 |
2025-11-11 14:55:30 | 2025-11-11 07:43:28 |
| CNNVD | cnnvd_CNNVD-201708-718 |
2025-11-11 15:09:52 | 2025-11-11 07:53:14 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-201708-718
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 8.1
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 1 -> 2
- data_sources: ['cve'] -> ['cve', 'nvd']