PT-2017-17291 · Cisco · Cisco Web Security Appliance
Publicado
2017-07-25
·
Atualizado
2021-04-05
·
CVE-2017-6751
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Web Security Appliance (WSA) versions 9.0.0-485 through 10.1.0-204
Description
A vulnerability in the web proxy functionality could allow an unauthenticated, remote attacker to forward traffic from the web proxy interface to the administrative management interface, effectively bypassing access controls. This issue affects both virtual and hardware versions of the Cisco Web Security Appliance.
Recommendations
For versions 9.0.0-485 through 10.1.0-204, consider restricting access to the administrative management interface until a patch is available.
As a temporary workaround, consider disabling the web proxy functionality to minimize the risk of exploitation.
Restrict access to the web proxy interface to minimize the risk of exploitation.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Web Security Appliance