CVE-2017-6639 is a critical vulnerability in Cisco Prime Data Center Network Manager (DCNM) versions 10.1(1) and 10.1(2) across Windows, Linux, and Virtual Appliance platforms. This flaw stems from an inadvertently enabled debugging tool lacking authentication and authorization. An unauthenticated, remote attacker can exploit this by connecting to the debugging tool via TCP. A successful exploit grants access to sensitive information or allows arbitrary code execution with root privileges, earning a CVSS score of 9.8 (Critical). While not listed in CISA's KEV, its high EPSS score and media coverage indicate significant community awareness, though no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.1\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:prime_data_center_network_manager:10.1\(1\):*:*:*:*:*:*:* | ||
10.1\(2\)CPE matchmatch criteria | cpe:2.3:a:cisco:prime_data_center_network_manager:10.1\(2\):*:*:*:*:*:*:* | ||
10.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:prime_data_center_network_manager:10.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.