VDB
CVE-2017-6708
CVE-2017-6708
PUBLISHED
CVSS 7.5 HIGH
A vulnerability in the symbolic link (symlink) creation functionality of the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to read sensitive files or execute malicious code on an affected system. The vulnerability is due to the absence of validation checks for the input that is used to create symbolic links. This vulnerability affects all releases of the Cisco Ultra Services Framework prior to Releases 5.0.3 and 5.1. Cisco Bug IDs: CSCvc76654.
EPSS 0.57% · 68.9th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
0.57%
68.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | Cisco Ultra Services Framework | Cisco Ultra Services Framework |
| cisco | ultra_services_framework | 0 |
Exploit Intelligence
Timeline
- Jul 5, 2017 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score