CVE-2017-6614

MEDIUM

Cisco Findit Network Probe - Information Disclosure

Title source: rule

Description

A vulnerability in the file-download feature of the web user interface for Cisco FindIT Network Probe Software 1.0.0 could allow an authenticated, remote attacker to download and view any system file by using the affected software. The vulnerability is due to the absence of role-based access control (RBAC) for file-download requests that are sent to the affected software. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow the attacker to download and view any system file by using the affected software. Cisco Bug IDs: CSCvd11628.

Scores

CVSS v3 6.5
EPSS 0.0034
EPSS Percentile 56.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-200
Status published

Affected Products (2)

cisco/findit_network_probe
n/a/Cisco FindIT < Cisco FindIT

Timeline

Published Apr 20, 2017
Tracked Since Feb 18, 2026