CVE Database
/

CVE-2017-6710

Back to search

CVE-2017-6710

Published: Aug 17, 2017

Modified: Sep 16, 2024

PUBLISHED

Description

A vulnerability in the Cisco Virtual Network Function (VNF) Element Manager could allow an authenticated, remote attacker to elevate privileges and run commands in the context of the root user on the server. The vulnerability is due to command settings that allow Cisco VNF Element Manager users to specify arbitrary commands that will run as root on the server. An attacker could use this setting to elevate privileges and run commands in the context of the root user on the server. Cisco Bug IDs: CSCvc76670. Known Affected Releases: prior to 5.0.4 and 5.1.4.

VendorProductVersions

Cisco Systems, Inc.

Virtual Network Function (VNF) Element Manager

affected
prior to 5.0.4 and 5.1.4

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now