PT-2017-4252 · Cisco · Cisco Umbrella Virtual Appliance+1

Published

2017-12-01

·

Updated

2023-08-17

·

CVE-2017-6679

CVSS v3.1

6.4

Medium

VectorAV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Umbrella Virtual Appliance versions prior to 2.1.0 Cisco Umbrella (affected versions not specified)
Description The issue is related to errors in resource release in the web interface of the Cisco Umbrella security service. Exploitation of this issue may allow an attacker to bypass existing security restrictions and gain unauthorized access to protected information. Additionally, an undocumented encrypted remote support tunnel in the Cisco Umbrella Virtual Appliance allowed authorized personnel from the Cisco Umbrella team to access the appliance remotely without explicit customer approval.
Recommendations For Cisco Umbrella Virtual Appliance versions prior to 2.1.0, update to version 2.1.0 or later, which requires explicit customer approval before an SSH tunnel from the VA to the Cisco terminating server can be established. For other affected versions of Cisco Umbrella, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2023-04952
CVE-2017-6679

Affected Products

Cisco Umbrella
Cisco Umbrella Virtual Appliance