Vulnerabilities > Cisco > Elastic Services Controller > 2.3.2

DATE CVE VULNERABILITY TITLE RISK
2021-01-20 CVE-2021-1312 Resource Exhaustion vulnerability in Cisco Elastic Services Controller
A vulnerability in the system resource management of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) to the health monitor API on an affected device.
network
low complexity
cisco CWE-400
7.5
2017-08-17 CVE-2017-6777 Information Exposure vulnerability in Cisco Elastic Services Controller 2.3/2.3(2)
A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to acquire sensitive system information.
network
low complexity
cisco CWE-200
4.0
2017-08-17 CVE-2017-6772 Information Exposure vulnerability in Cisco Elastic Services Controller 2.3(2)
A vulnerability in Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to view sensitive information.
network
low complexity
cisco CWE-200
4.0
2017-06-13 CVE-2017-6696 Information Exposure vulnerability in Cisco Elastic Services Controller 2.3(2)
A vulnerability in the file system of Cisco Elastic Services Controllers could allow an authenticated, local attacker to gain access to sensitive user credentials that are stored in an affected system.
local
low complexity
cisco CWE-200
2.1
2017-06-13 CVE-2017-6691 Information Exposure vulnerability in Cisco Elastic Services Controller 2.3(2)
A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to access sensitive information on an affected system.
network
low complexity
cisco CWE-200
4.0