CVE-2017-6778 (CNNVD-201708-792)
中文标题:
Cisco Ultra Services Platform Elastic Services Controller Web界面信息泄露漏洞
英文标题:
A vulnerability in the Elastic Services Controller (ESC) web interface of the Cisco Ultra Services P...
漏洞描述
中文描述:
Cisco Ultra Services Platform是美国思科(Cisco)公司的一个智能在线服务交付平台。Elastic Services Controller(ESC)是其中的一个开源的模块化系统。 Cisco Ultra Services Platform 21.0.v0.65839版本中的ESC Web界面存在信息泄露漏洞。远程攻击者可通过向受影响的设备发送GET请求利用该漏洞浏览有关Ultra Services Platform的部署。
英文描述:
A vulnerability in the Elastic Services Controller (ESC) web interface of the Cisco Ultra Services Platform could allow an authenticated, remote attacker to acquire sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker could exploit this vulnerability by sending a GET request to a vulnerable device. An exploit could allow the attacker to view information regarding the Ultra Services Platform deployment. Cisco Bug IDs: CSCvd76406. Known Affected Releases: 21.0.v0.65839.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco Systems, Inc. | Ultra Services Platform | 21.0.v0.65839 | - | - |
cpe:2.3:a:cisco_systems,_inc.:ultra_services_platform:21.0.v0.65839:*:*:*:*:*:*:*
|
| cisco | ultra_services_platform | 21.0.v0.65839 | - | - |
cpe:2.3:a:cisco:ultra_services_platform:21.0.v0.65839:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2017-6778 |
2025-11-11 15:19:31 | 2025-11-11 07:34:51 |
| NVD | nvd_CVE-2017-6778 |
2025-11-11 14:55:30 | 2025-11-11 07:43:28 |
| CNNVD | cnnvd_CNNVD-201708-792 |
2025-11-11 15:09:52 | 2025-11-11 07:53:14 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 信息泄露
- cnnvd_id: 未提取 -> CNNVD-201708-792
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 6.5
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 1 -> 2
- data_sources: ['cve'] -> ['cve', 'nvd']