CVE-2017-3847: XSS
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. More Information: CSCvc72741. Known Affected Releases: 6.2.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Firepower Management Centerto a version that resolves this vulnerability.Fixed in 6.2.1Patch CSCvc72741
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3847?
CVE-2017-3847 is classified as a high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2017-3847?
To fix CVE-2017-3847, update your Cisco Firepower Management Center to a version that is not vulnerable, specifically beyond 6.2.1.
Who is affected by CVE-2017-3847?
Users of Cisco Secure Firewall Management Center and Cisco Firepower Management Center using version 6.2.1 are affected by CVE-2017-3847.
What type of attack can be conducted using CVE-2017-3847?
CVE-2017-3847 allows an authenticated remote attacker to conduct a cross-site scripting (XSS) attack.
When was CVE-2017-3847 disclosed?
CVE-2017-3847 was disclosed in February 2017.