CVE-2017-3814: Input Validation
A vulnerability in Cisco Firepower System Software could allow an unauthenticated, remote attacker to maliciously bypass the appliance's ability to block certain web content, aka a URL Bypass. More Information: CSCvb93980. Known Affected Releases: 5.3.0 5.4.0 6.0.0 6.0.1 6.1.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Firepower System Softwareto a version that resolves this vulnerability.Fixed in 5.3.0Patch CSCvb93980 - Upgrade
Upgrade
Cisco Firepower System Softwareto a version that resolves this vulnerability.Fixed in 5.4.0Patch CSCvb93980 - Upgrade
Upgrade
Cisco Firepower System Softwareto a version that resolves this vulnerability.Fixed in 6.0.0Patch CSCvb93980 - Upgrade
Upgrade
Cisco Firepower System Softwareto a version that resolves this vulnerability.Fixed in 6.0.1Patch CSCvb93980 - Upgrade
Upgrade
Cisco Firepower System Softwareto a version that resolves this vulnerability.Fixed in 6.1.0Patch CSCvb93980
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3814?
CVE-2017-3814 is considered a high severity vulnerability that allows unauthenticated remote attackers to bypass URL filtering.
How do I fix CVE-2017-3814?
To fix CVE-2017-3814, upgrade to the latest version of Cisco Firepower System Software as specified in the advisory.
What product versions are affected by CVE-2017-3814?
CVE-2017-3814 affects Cisco Secure Firewall Management Center and Cisco Firepower Management Center Software versions 5.3.0, 5.4.0, 6.0.0, 6.0.1, and 6.1.0.
Can CVE-2017-3814 be exploited locally?
CVE-2017-3814 cannot be exploited locally as it requires remote access and does not require authentication.
What is the impact of CVE-2017-3814 on web content filtering?
CVE-2017-3814 impacts the appliance's ability to block certain web content, effectively allowing attacks to bypass content filtering mechanisms.