CVE-2017-6597: OS Command Injection
A vulnerability in the local-mgmt CLI command of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61394 CSCvb86816. Known Affected Releases: 2.0(1.68) 3.1(1k)A. Known Fixed Releases: 92.2(1.101) 92.1(1.1658) 2.0(1.115).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Unified Computing System (UCS) Manager CLI (local-mgmt) / Cisco Firepower 4100 NGFW / Cisco Firepower 9300 Security Applianceto a version that resolves this vulnerability.Fixed in 92.2(1.101) - Upgrade
Upgrade
Cisco Unified Computing System (UCS) Manager CLI (local-mgmt) / Cisco Firepower 4100 NGFW / Cisco Firepower 9300 Security Applianceto a version that resolves this vulnerability.Fixed in 92.1(1.1658) - Upgrade
Upgrade
Cisco Unified Computing System (UCS) Manager CLI (local-mgmt) / Cisco Firepower 4100 NGFW / Cisco Firepower 9300 Security Applianceto a version that resolves this vulnerability.Fixed in 2.0(1.115)
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6597?
CVE-2017-6597 has a severity score of 7.8, indicating it is a high-risk vulnerability.
How does CVE-2017-6597 impact Cisco devices?
CVE-2017-6597 allows authenticated local attackers to perform command injection attacks on affected Cisco devices.
What versions are affected by CVE-2017-6597?
CVE-2017-6597 affects Cisco Unified Computing System version 3.1(1k)a and Cisco Firepower Extensible Operating System version 2.0(1.68).
How do I fix CVE-2017-6597?
To fix CVE-2017-6597, update your Cisco devices to the latest software versions as recommended by Cisco.
What are the common exploit types for CVE-2017-6597?
CVE-2017-6597 is commonly associated with command injection attacks.