CVE-2017-6683 is a critical arbitrary command execution vulnerability in the esc_listener.py script of Cisco Elastic Services Controllers. An authenticated, remote attacker can exploit this flaw to execute commands as the tomcat user, leading to high impact on confidentiality, integrity, and availability. With a CVSS score of 8.8 (High), it requires low attack complexity and no user interaction. While not currently listed on the KEV catalog or Hot List, and lacking public exploit code or significant community discussion, its high FAUCET Risk Score of 84/100 indicates a serious potential threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2\(9.76\)CPE matchmatch criteria | cpe:2.3:a:cisco:elastic_services_controller:2.2\(9.76\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.