« Volver al listado

Cisco

Cisco Elastic Services Controller: vulnerabilidades y CVE

Cisco Elastic Services Controller tiene 19 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE19
Últimos 12 meses0
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2021-1312Alta (7.5)2.5%—20 ene 2021
A vulnerability in the system resource management of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) to the health monitor API on an affected…
CVE-2019-1867Crítica (10)30%—10 may 2019
A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on the REST API. The vulnerability is due to improper validation of API…
CVE-2018-0121Crítica (9.8)2.5%—22 feb 2018
A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to bypass authentication and execute…
CVE-2018-0106Baja (3.3)0.30%—18 ene 2018
A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an unauthenticated, local attacker to access sensitive information on a targeted system. The vulnerability is due to…
CVE-2017-6786Media (6.3)0.30%—17 ago 2017
A vulnerability in Cisco Elastic Services Controller could allow an authenticated, local, unprivileged attacker to access sensitive information, including credentials for system accounts, on an affected system. The…
CVE-2017-6777Media (4.9)1.2%—17 ago 2017
A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to acquire sensitive system information. The vulnerability is due to insufficient…
CVE-2017-6776Media (6.1)0.87%—17 ago 2017
A vulnerability in the web framework of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. The…
CVE-2017-6772Media (4.3)0.94%—17 ago 2017
A vulnerability in Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to insufficient protection of sensitive data. An attacker…
CVE-2017-6713Crítica (9.8)2.9%—6 jul 2017
A vulnerability in the Play Framework of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to gain full access to the affected system. The vulnerability is due to static, default…
CVE-2017-6712Alta (8.8)2.0%—6 jul 2017
A vulnerability in certain commands of Cisco Elastic Services Controller could allow an authenticated, remote attacker to elevate privileges to root and run dangerous commands on the server. The vulnerability occurs…
CVE-2017-6697Media (6.5)1.2%—13 jun 2017
A vulnerability in the web interface of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to access sensitive system credentials that are stored in an affected system. More Information:…
CVE-2017-6696Media (5.5)0.31%—13 jun 2017
A vulnerability in the file system of Cisco Elastic Services Controllers could allow an authenticated, local attacker to gain access to sensitive user credentials that are stored in an affected system. More Information:…
CVE-2017-6693Media (5.5)0.27%—13 jun 2017
A vulnerability in the ConfD server component of Cisco Elastic Services Controllers could allow an authenticated, local attacker to access information stored in the file system of an affected system, aka Unauthorized…
CVE-2017-6691Media (6.5)1.2%—13 jun 2017
A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to access sensitive information on an affected system. More Information: CSCvd29403. Known Affected…
CVE-2017-6689Alta (8.8)1.5%—13 jun 2017
A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the admin user, aka an Insecure Default Administrator Credentials…
CVE-2017-6688Alta (8.8)2.3%—13 jun 2017
A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux root user, aka an Insecure Default Password Vulnerability. More…
CVE-2017-6684Alta (8.8)2.3%—13 jun 2017
A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux admin user, aka an Insecure Default Credentials Vulnerability. More…
CVE-2017-6683Alta (8.8)5.9%—13 jun 2017
A vulnerability in the esc_listener.py script of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to execute arbitrary commands as the tomcat user on an affected system, aka an…
CVE-2017-6682Alta (8.8)2.2%—13 jun 2017
A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to run arbitrary commands as the Linux tomcat user on an affected system. More Information:…

📰 Noticias relacionadas

Otros productos de Cisco