CVE-2017-6714 describes a critical vulnerability in the AutoIT service of Cisco Ultra Services Framework Staging Server, affecting all releases prior to 5.0.3 and 5.1. This flaw allows an unauthenticated, remote attacker to execute arbitrary shell commands as the Linux root user due to improper shell invocations. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk, enabling complete compromise of confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not listed in KEV, it has garnered some community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.0.2CPE matchmatch criteria | cpe:2.3:a:cisco:ultra_services_framework_staging_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.