CVE-2017-3822: Input Validation
A vulnerability in the logging subsystem of the Cisco Firepower Threat Defense (FTD) Firepower Device Manager (FDM) could allow an unauthenticated, remote attacker to add arbitrary entries to the audit log. This vulnerability affects Cisco Firepower Threat Defense Software versions 6.1.x on the following vulnerable products that have enabled FDM: ASA5506-X ASA5506W-X ASA5506H-X ASA5508-X ASA5516-X ASA5512-X ASA5515-X ASA5525-X ASA5545-X ASA5555-X. More Information: CSCvb86860. Known Affected Releases: FRANGELICO. Known Fixed Releases: 6.2.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Firepower Threat Defense (FTD) Firepower Device Manager (FDM)to a version that resolves this vulnerability.Fixed in 6.2.0Patch CSCvb86860
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3822?
CVE-2017-3822 is considered to be a medium severity vulnerability.
How do I fix CVE-2017-3822?
To fix CVE-2017-3822, upgrade Cisco Firepower Threat Defense Software to a version that is not vulnerable.
Who is affected by CVE-2017-3822?
CVE-2017-3822 affects users of Cisco Firepower Threat Defense Software version 6.1.x.
Can CVE-2017-3822 be exploited remotely?
Yes, CVE-2017-3822 can be exploited by an unauthenticated remote attacker.
What impact does CVE-2017-3822 have on security?
CVE-2017-3822 may allow attackers to manipulate audit logs, potentially undermining the integrity of security logging.