Vulnerabilities > Cisco > Ultra Services Framework > 21.0.0

DATE CVE VULNERABILITY TITLE RISK
2017-06-13 CVE-2017-6681 Information Exposure vulnerability in Cisco Ultra Services Framework 21.0.0
A vulnerability in the AutoVNF VNFStagingView class of Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to execute a relative path traversal attack, enabling an attacker to read sensitive files on the system.
network
low complexity
cisco CWE-200
7.5
2017-06-13 CVE-2017-6680 Improper Input Validation vulnerability in Cisco Ultra Services Framework 21.0.0
A vulnerability in the AutoVNF logging function of Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to create arbitrary directories on the affected system.
network
low complexity
cisco CWE-20
7.5