PT-2017-4252 · Cisco · Cisco Umbrella Virtual Appliance+1
Published
2017-12-01
·
Updated
2023-08-17
·
CVE-2017-6679
CVSS v3.1
6.4
Medium
| Vector | AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Umbrella Virtual Appliance versions prior to 2.1.0
Cisco Umbrella (affected versions not specified)
Description
The issue is related to errors in resource release in the web interface of the Cisco Umbrella security service. Exploitation of this issue may allow an attacker to bypass existing security restrictions and gain unauthorized access to protected information. Additionally, an undocumented encrypted remote support tunnel in the Cisco Umbrella Virtual Appliance allowed authorized personnel from the Cisco Umbrella team to access the appliance remotely without explicit customer approval.
Recommendations
For Cisco Umbrella Virtual Appliance versions prior to 2.1.0, update to version 2.1.0 or later, which requires explicit customer approval before an SSH tunnel from the VA to the Cisco terminating server can be established.
For other affected versions of Cisco Umbrella, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Umbrella
Cisco Umbrella Virtual Appliance