Elastic Services Controller
Vendor:
First CVE: Jun 13, 2017 · Active for 9 years
19
Total CVEs
More Total CVEs than 93% of tracked products
4.8
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Elastic Services Controller over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 13, 2017
9 years ago
Most Recent CVE
Jan 20, 2021
2,011 days ago
CVE Severity & Scoring
Elastic Services Controller19 CVEs
42%
37%
16%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (21.1%)
Network15 (78.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None18 (94.7%)
Unknown0 (0.0%)
Required1 (5.3%)
Privileges Required
Low13 (68.4%)
High1 (5.3%)
None5 (26.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-1867CRITICAL A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on the REST API. The vulnerabili | May 10, 2019 | 10.0 | 48 | NO | NO |
CVE-2018-0121CRITICAL A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to | Feb 22, 2018 | 9.8 | 31 | NO | NO |
CVE-2017-6688HIGH A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux root user, aka an Insecure Default | Jun 13, 2017 | 8.8 | 28 | NO | NO |
CVE-2017-6683HIGH A vulnerability in the esc_listener.py script of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to execute arbitrary commands as the tomcat user o | Jun 13, 2017 | 8.8 | 27 | NO | NO |
CVE-2021-1312HIGH A vulnerability in the system resource management of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) to t | Jan 20, 2021 | 7.5 | 25 | NO | NO |
CVE-2017-6713CRITICAL A vulnerability in the Play Framework of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to gain full access to the affected system. The vul | Jul 6, 2017 | 9.8 | 25 | NO | NO |
CVE-2017-6689HIGH A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the admin user, aka an Insec | Jun 13, 2017 | 8.8 | 24 | NO | NO |
CVE-2017-6712HIGH A vulnerability in certain commands of Cisco Elastic Services Controller could allow an authenticated, remote attacker to elevate privileges to root and run dangerous commands on t | Jul 6, 2017 | 8.8 | 22 | NO | NO |
CVE-2017-6684HIGH A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux admin user, aka an Insecure Default | Jun 13, 2017 | 8.8 | 22 | NO | NO |
CVE-2017-6682HIGH A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to run arbitrary commands as the Linux tomcat user on an affect | Jun 13, 2017 | 8.8 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Elastic Services Controller
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.0.0 | 1 | 9.8 | 2.6% | 0 | 0 |
| 2.3\(2\) | 4 | 5.3 | 0.9% | 0 | 0 |
| 2.3\(1\) | 2 | 5.8 | 0.6% | 0 | 0 |
| 2.3.0 | 2 | 9.3 | 2.5% | 0 | 0 |
| 2.3 | 1 | 4.9 | 1.2% | 0 | 0 |
| 2.2\(9.76\) | 8 | 7.5 | 1.8% | 0 | 0 |
| 2.2.0 | 2 | 9.3 | 2.5% | 0 | 0 |
| 21.0.0 | 1 | 8.8 | 2.3% | 0 | 0 |
| 2.1.0 | 2 | 9.3 | 2.5% | 0 | 0 |
| 2.0 | 2 | 9.3 | 2.5% | 0 | 0 |
| 1.1.0 | 2 | 9.3 | 2.5% | 0 | 0 |
| 1.0.0 | 2 | 9.3 | 2.5% | 0 | 0 |