AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-6708

CRITICAL · CVSS 9.8 EPSS 1.46%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-07-06 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It affects Cisco. It may be remotely exploitable.

CVE
CVE-2017-6708
Severity
CRITICAL
CVSS
9.8
EPSS
1.46%
Cisco

Original NVD Description

A vulnerability in the symbolic link (symlink) creation functionality of the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to read sensitive files or execute malicious code on an affected system. The vulnerability is due to the absence of validation checks for the input that is used to create symbolic links. This vulnerability affects all releases of the Cisco Ultra Services Framework prior to Releases 5.0.3 and 5.1. Cisco Bug IDs: CSCvc76654.

Related CVEs

Other vulnerabilities affecting the same vendor(s)