VDB

CVE-2017-6639

CVE-2017-6639 PUBLISHED CVSS 10 CRITICAL

A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to access sensitive information or execute arbitrary code with root privileges on an affected system. The vulnerability is due to the lack of authentication and authorization mechanisms for a debugging tool that was inadvertently enabled in the affected software. An attacker could exploit this vulnerability by remotely connecting to the debugging tool via TCP. A successful exploit could allow the attacker to access sensitive information about the affected software or execute arbitrary code with root privileges on the affected system. This vulnerability affects Cisco Prime Data Center Network Manager (DCNM) Software Releases 10.1(1) and 10.1(2) for Microsoft Windows, Linux, and Virtual Appliance platforms. Cisco Bug IDs: CSCvd09961.

EPSS 40.74% · 97.5th percentile

Risk Scores

CVSS 2.0
10
EPSS Score
40.74%
97.5th percentile

Affected Products

VendorProductVersions
CiscoN/A
ciscoprime_data_center_network_manager10.1\(1\), 10.1\(2\), 10.1.0
n/aCisco Prime Data Center Network Manager Debug Remote Code Execution VulnerabilityCisco Prime Data Center Network Manager Debug Remote Code Execution Vulnerability

Timeline

  • Jun 7, 2017 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 18, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›