CVE-2017-6598: Medium severity Cisco Firepower Extensible Operating System vulnerability
A vulnerability in the debug plug-in functionality of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to execute arbitrary commands, aka Privilege Escalation. More Information: CSCvb86725 CSCvb86797. Known Affected Releases: 2.0(1.68) 3.1(1k)A. Known Fixed Releases: 92.2(1.105) 92.1(1.1733) 2.1(1.69).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Unified Computing System (UCS) Managerto a version that resolves this vulnerability.Fixed in 2.1(1.69) - Upgrade
Upgrade
Cisco Firepower 4100 Series Next-Generation Firewall (NGFW)to a version that resolves this vulnerability.Fixed in 92.1(1.1733) - Upgrade
Upgrade
Cisco Firepower 9300 Security Applianceto a version that resolves this vulnerability.Fixed in 92.2(1.105) - Compensating control
If immediate upgrade is not possible, restrict management/SSH access so only trusted administrators can reach the system (mitigate authenticated local attacker capability).
- Compensating control
Review audit logs for evidence of use of the debug plug-in functionality for command execution attempts (CSCvb86725, CSCvb86797).
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6598?
The severity of CVE-2017-6598 is rated as high with a score of 6.7.
How do I fix CVE-2017-6598?
To mitigate CVE-2017-6598, update the Cisco Unified Computing System Manager and Cisco Firepower software to the latest versions provided by Cisco.
What systems are affected by CVE-2017-6598?
CVE-2017-6598 affects Cisco Unified Computing System Manager and Cisco Firepower 4100/9300 Series devices.
What type of vulnerability is CVE-2017-6598?
CVE-2017-6598 is a privilege escalation vulnerability that allows an authenticated local attacker to execute arbitrary commands.
Can CVE-2017-6598 be exploited remotely?
CVE-2017-6598 can only be exploited by an authenticated local attacker, not remotely.