PatchSiren cyber security CVE debrief
CVE-2017-3844 Cisco CVE debrief
CVE-2017-3844 is an authenticated remote information-disclosure issue in Cisco Prime Collaboration Assurance. According to Cisco and NVD, the affected UI exporting functions could let a logged-in attacker view directory listings and download files in vulnerable releases.
- Vendor
- Cisco
- Product
- Prime Collaboration Assurance
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-22
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-22
- Advisory updated
- 2026-05-13
Who should care
Administrators and security teams running Cisco Prime Collaboration Assurance 11.0, 11.1, or 11.5 should care most, especially if the product is exposed to a broad internal user base or multiple operator accounts.
Technical summary
NVD lists the vulnerability as CVSS 3.0 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N with CWE-20. The issue is limited to Cisco Prime Collaboration Assurance versions 11.0.0, 11.1.0, and 11.5.0, and Cisco notes that versions prior to 11.0 are not vulnerable. The impact described in the source corpus is disclosure of file directory listings and file downloads through exporting functions in the user interface.
Defensive priority
Medium. The issue does not appear to enable code execution or availability impact, but it can expose files to an authenticated attacker and should be remediated on any affected deployment.
Recommended defensive actions
- Confirm whether Cisco Prime Collaboration Assurance is running version 11.0, 11.1, or 11.5.
- Apply Cisco's remediation guidance from the vendor advisory linked in NVD.
- Restrict access to the application UI to only trusted administrative users and networks.
- Review authentication logs and file-access activity for unexpected browsing or downloads.
- If sensitive files may have been exposed, assess their contents and rotate credentials or secrets stored on the system.
Evidence notes
The debrief is based on the CVE description supplied here, NVD's CVSS vector and affected CPE entries, and the Cisco vendor advisory referenced by NVD. The official record states the issue affects Cisco Prime Collaboration Assurance 11.0, 11.1, and 11.5, while earlier versions are not vulnerable.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-3844 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-3844
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-3844 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3844
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-pcp2
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.