CVE-2017-3809: Input Validation
A vulnerability in the Policy deployment module of the Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to prevent deployment of a complete and accurate rule base. More Information: CSCvb95281. Known Affected Releases: 6.1.0 6.2.0. Known Fixed Releases: 6.1.0.1 6.2.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Firepower Management Center (FMC) - Policy deployment moduleto a version that resolves this vulnerability.Fixed in 6.1.0.1Patch CSCvb95281 - Upgrade
Upgrade
Cisco Firepower Management Center (FMC) - Policy deployment moduleto a version that resolves this vulnerability.Fixed in 6.2.0Patch CSCvb95281
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3809?
CVE-2017-3809 is classified as a high severity vulnerability.
How do I fix CVE-2017-3809?
To remediate CVE-2017-3809, it is recommended to upgrade to a fixed release of the Cisco software.
Which versions are affected by CVE-2017-3809?
CVE-2017-3809 affects Cisco Secure Firewall Management Center versions 6.1.0 and 6.2.0.
Can CVE-2017-3809 be exploited remotely?
Yes, CVE-2017-3809 can be exploited by an unauthenticated, remote attacker.
What is the impact of CVE-2017-3809?
CVE-2017-3809 allows an attacker to prevent the deployment of a complete and accurate rule base.