PT-2017-17291 · Cisco · Cisco Web Security Appliance

Published

2017-07-25

·

Updated

2021-04-05

·

CVE-2017-6751

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco Web Security Appliance (WSA) versions 9.0.0-485 through 10.1.0-204
Description A vulnerability in the web proxy functionality could allow an unauthenticated, remote attacker to forward traffic from the web proxy interface to the administrative management interface, effectively bypassing access controls. This issue affects both virtual and hardware versions of the Cisco Web Security Appliance.
Recommendations For versions 9.0.0-485 through 10.1.0-204, consider restricting access to the administrative management interface until a patch is available. As a temporary workaround, consider disabling the web proxy functionality to minimize the risk of exploitation. Restrict access to the web proxy interface to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6751

Affected Products

Cisco Web Security Appliance