First published: Wed Feb 22 2017(Updated: )
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. More Information: CSCvc72741. Known Affected Releases: 6.2.1.
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure Firewall Management Center | =6.2.1 | |
Cisco Firepower Management Center Software | =6.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3847 is classified as a high severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2017-3847, update your Cisco Firepower Management Center to a version that is not vulnerable, specifically beyond 6.2.1.
Users of Cisco Secure Firewall Management Center and Cisco Firepower Management Center using version 6.2.1 are affected by CVE-2017-3847.
CVE-2017-3847 allows an authenticated remote attacker to conduct a cross-site scripting (XSS) attack.
CVE-2017-3847 was disclosed in February 2017.