PT-2017-17291 · Cisco · Cisco Web Security Appliance

Publicado

2017-07-25

·

Atualizado

2021-04-05

·

CVE-2017-6751

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco Web Security Appliance (WSA) versions 9.0.0-485 through 10.1.0-204
Description A vulnerability in the web proxy functionality could allow an unauthenticated, remote attacker to forward traffic from the web proxy interface to the administrative management interface, effectively bypassing access controls. This issue affects both virtual and hardware versions of the Cisco Web Security Appliance.
Recommendations For versions 9.0.0-485 through 10.1.0-204, consider restricting access to the administrative management interface until a patch is available. As a temporary workaround, consider disabling the web proxy functionality to minimize the risk of exploitation. Restrict access to the web proxy interface to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-6751

Produtos afetados

Cisco Web Security Appliance