ID

VAR-201705-3671


CVE

CVE-2017-6652


TITLE

Cisco TelePresence IX5000 Series Web Vulnerability to access arbitrary files on affected devices in the framework

Trust: 0.8

sources: JVNDB: JVNDB-2017-004119

DESCRIPTION

A vulnerability in the web framework of the Cisco TelePresence IX5000 Series could allow an unauthenticated, remote attacker to access arbitrary files on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by using directory traversal techniques to read files within the Cisco TelePresence IX5000 Series filesystem. This vulnerability affects Cisco TelePresence IX5000 Series devices running software version 8.2.0. Cisco Bug IDs: CSCvc52325. Information harvested may aid in launching further attacks. The solution provides components such as audio and video space, which can provide remote participants with a face-to-face virtual meeting room effect

Trust: 2.07

sources: NVD: CVE-2017-6652 // JVNDB: JVNDB-2017-004119 // BID: 98519 // VULHUB: VHN-114855 // VULMON: CVE-2017-6652

AFFECTED PRODUCTS

vendor:ciscomodel:telepresence ix5000scope:eqversion:8.2.0_base

Trust: 1.6

vendor:ciscomodel:telepresence ix5000scope:eqversion:8.2.0

Trust: 0.8

vendor:ciscomodel:telepresence ix5000 seriesscope:eqversion:8.2

Trust: 0.3

vendor:ciscomodel:telepresence ix5000 seriesscope:neversion:8.2.1

Trust: 0.3

sources: BID: 98519 // JVNDB: JVNDB-2017-004119 // CNNVD: CNNVD-201705-846 // NVD: CVE-2017-6652

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-6652
value: HIGH

Trust: 1.0

NVD: CVE-2017-6652
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201705-846
value: MEDIUM

Trust: 0.6

VULHUB: VHN-114855
value: MEDIUM

Trust: 0.1

VULMON: CVE-2017-6652
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-6652
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-114855
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-6652
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-114855 // VULMON: CVE-2017-6652 // JVNDB: JVNDB-2017-004119 // CNNVD: CNNVD-201705-846 // NVD: CVE-2017-6652

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

problemtype:CWE-22

Trust: 1.9

sources: VULHUB: VHN-114855 // JVNDB: JVNDB-2017-004119 // NVD: CVE-2017-6652

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201705-846

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201705-846

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-004119

PATCH

title:cisco-sa-20170517-telepresence-ix5000url:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170517-telepresence-ix5000

Trust: 0.8

title:Cisco TelePresence IX5000 Series Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=70377

Trust: 0.6

title:Cisco: Cisco TelePresence IX5000 Series Directory Traversal Vulnerabilityurl:https://vulmon.com/vendoradvisory?qidtp=cisco_security_advisories_and_alerts_ciscoproducts&qid=cisco-sa-20170517-telepresence-ix5000

Trust: 0.1

sources: VULMON: CVE-2017-6652 // JVNDB: JVNDB-2017-004119 // CNNVD: CNNVD-201705-846

EXTERNAL IDS

db:NVDid:CVE-2017-6652

Trust: 2.9

db:BIDid:98519

Trust: 1.5

db:SECTRACKid:1038509

Trust: 1.2

db:JVNDBid:JVNDB-2017-004119

Trust: 0.8

db:CNNVDid:CNNVD-201705-846

Trust: 0.7

db:NSFOCUSid:36721

Trust: 0.6

db:VULHUBid:VHN-114855

Trust: 0.1

db:VULMONid:CVE-2017-6652

Trust: 0.1

sources: VULHUB: VHN-114855 // VULMON: CVE-2017-6652 // BID: 98519 // JVNDB: JVNDB-2017-004119 // CNNVD: CNNVD-201705-846 // NVD: CVE-2017-6652

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20170517-telepresence-ix5000

Trust: 2.2

url:http://www.securityfocus.com/bid/98519

Trust: 1.3

url:http://www.securitytracker.com/id/1038509

Trust: 1.2

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-6652

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-6652

Trust: 0.8

url:http://www.nsfocus.net/vulndb/36721

Trust: 0.6

url:http://www.cisco.com/

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/22.html

Trust: 0.1

url:https://cwe.mitre.org/data/definitions/20.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-114855 // VULMON: CVE-2017-6652 // BID: 98519 // JVNDB: JVNDB-2017-004119 // CNNVD: CNNVD-201705-846 // NVD: CVE-2017-6652

CREDITS

Cisco

Trust: 0.3

sources: BID: 98519

SOURCES

db:VULHUBid:VHN-114855
db:VULMONid:CVE-2017-6652
db:BIDid:98519
db:JVNDBid:JVNDB-2017-004119
db:CNNVDid:CNNVD-201705-846
db:NVDid:CVE-2017-6652

LAST UPDATE DATE

2025-04-20T23:42:13.433000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-114855date:2017-07-08T00:00:00
db:VULMONid:CVE-2017-6652date:2017-07-08T00:00:00
db:BIDid:98519date:2017-05-25T14:00:00
db:JVNDBid:JVNDB-2017-004119date:2017-06-16T00:00:00
db:CNNVDid:CNNVD-201705-846date:2017-05-25T00:00:00
db:NVDid:CVE-2017-6652date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:VULHUBid:VHN-114855date:2017-05-18T00:00:00
db:VULMONid:CVE-2017-6652date:2017-05-18T00:00:00
db:BIDid:98519date:2017-05-17T00:00:00
db:JVNDBid:JVNDB-2017-004119date:2017-06-16T00:00:00
db:CNNVDid:CNNVD-201705-846date:2017-05-25T00:00:00
db:NVDid:CVE-2017-6652date:2017-05-18T19:29:00.313