CVE-2017-6792

CVE-2017-6792

Vendor N/A
Product Cisco Prime Collaboration Provisioning Tool
Weakness CWE-20 · Input validation
Published September 7, 2017
Last update August 5, 2024

CVSS base score

What the vulnerability does

01Description

A vulnerability in the batch provisioning feature in Cisco Prime Collaboration Provisioning Tool could allow an authenticated, remote attacker to overwrite system files as root. The vulnerability is due to lack of input validation of the parameters in BatchFileName and Directory. An attacker could exploit this vulnerability by manipulating the parameters of the batch action file function. Cisco Bug IDs: CSCvd61766.

Key dates

02Disclosure timeline

September 7, 2017 CVE published
August 5, 2024 Record updated