CVE-2017-6710 describes a privilege escalation vulnerability in Cisco Virtual Network Function (VNF) Element Manager versions prior to 5.0.4 and 5.1.4. An authenticated, remote attacker can exploit this flaw by specifying arbitrary commands that the VNF Element Manager will execute as the root user. This allows the attacker to elevate their privileges and run commands with root access on the server. The vulnerability carries a high CVSS score of 8.1, indicating a significant risk due to its network-based attack vector, low attack complexity, and high impact on integrity and availability. While requiring prior authentication, successful exploitation grants full control over the affected system. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has also received minimal community discussion and media coverage, suggesting a low level of public awareness or active threat intelligence surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.1.3CPE matchmatch criteria | cpe:2.3:a:cisco:virtual_network_function_element_manager:*:*:*:*:*:*:*:* | ||
<= 5.0.3CPE matchmatch criteria | cpe:2.3:a:cisco:virtual_network_function_element_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.