ID

VAR-201706-0574


CVE

CVE-2017-6695


TITLE

Cisco Ultra Services Platform of ConfD Vulnerability to view important information on the server

Trust: 0.8

sources: JVNDB: JVNDB-2017-004818

DESCRIPTION

A vulnerability in the ConfD server in Cisco Ultra Services Platform could allow an authenticated, local attacker to view sensitive information. More Information: CSCvd29398. Known Affected Releases: 21.0.v0.65839. An attacker can exploit this issue to obtain sensitive information that may aid in further attacks. This issue is being tracked by Cisco bug ID CSCvd29398. ConfD server is one of the management framework components

Trust: 1.98

sources: NVD: CVE-2017-6695 // JVNDB: JVNDB-2017-004818 // BID: 98963 // VULHUB: VHN-114898

AFFECTED PRODUCTS

vendor:ciscomodel:ultra services platformscope:eqversion:21.0.v0.65839

Trust: 1.6

vendor:ciscomodel:ultra services platformscope: - version: -

Trust: 0.8

vendor:ciscomodel:ultra services platformscope:eqversion:0

Trust: 0.3

sources: BID: 98963 // JVNDB: JVNDB-2017-004818 // CNNVD: CNNVD-201706-358 // NVD: CVE-2017-6695

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-6695
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-6695
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201706-358
value: LOW

Trust: 0.6

VULHUB: VHN-114898
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2017-6695
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-114898
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-6695
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-114898 // JVNDB: JVNDB-2017-004818 // CNNVD: CNNVD-201706-358 // NVD: CVE-2017-6695

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-114898 // JVNDB: JVNDB-2017-004818 // NVD: CVE-2017-6695

THREAT TYPE

local

Trust: 0.9

sources: BID: 98963 // CNNVD: CNNVD-201706-358

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201706-358

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-004818

PATCH

title:cisco-sa-20170607-usp2url:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-usp2

Trust: 0.8

title:Cisco Ultra Services Platform ConfD Repair measures for server information disclosure vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=74430

Trust: 0.6

sources: JVNDB: JVNDB-2017-004818 // CNNVD: CNNVD-201706-358

EXTERNAL IDS

db:NVDid:CVE-2017-6695

Trust: 2.8

db:BIDid:98963

Trust: 2.0

db:JVNDBid:JVNDB-2017-004818

Trust: 0.8

db:CNNVDid:CNNVD-201706-358

Trust: 0.7

db:VULHUBid:VHN-114898

Trust: 0.1

sources: VULHUB: VHN-114898 // BID: 98963 // JVNDB: JVNDB-2017-004818 // CNNVD: CNNVD-201706-358 // NVD: CVE-2017-6695

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20170607-usp2

Trust: 2.0

url:http://www.securityfocus.com/bid/98963

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-6695

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-6695

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-114898 // BID: 98963 // JVNDB: JVNDB-2017-004818 // CNNVD: CNNVD-201706-358 // NVD: CVE-2017-6695

CREDITS

Cisco

Trust: 0.9

sources: BID: 98963 // CNNVD: CNNVD-201706-358

SOURCES

db:VULHUBid:VHN-114898
db:BIDid:98963
db:JVNDBid:JVNDB-2017-004818
db:CNNVDid:CNNVD-201706-358
db:NVDid:CVE-2017-6695

LAST UPDATE DATE

2025-04-20T23:38:30.206000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-114898date:2017-06-20T00:00:00
db:BIDid:98963date:2017-06-07T00:00:00
db:JVNDBid:JVNDB-2017-004818date:2017-07-07T00:00:00
db:CNNVDid:CNNVD-201706-358date:2017-09-06T00:00:00
db:NVDid:CVE-2017-6695date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:VULHUBid:VHN-114898date:2017-06-13T00:00:00
db:BIDid:98963date:2017-06-07T00:00:00
db:JVNDBid:JVNDB-2017-004818date:2017-07-07T00:00:00
db:CNNVDid:CNNVD-201706-358date:2017-06-07T00:00:00
db:NVDid:CVE-2017-6695date:2017-06-13T06:29:01.690