First published: Fri Apr 07 2017(Updated: )
A vulnerability in the debug plug-in functionality of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to execute arbitrary commands, aka Privilege Escalation. More Information: CSCvb86725 CSCvb86797. Known Affected Releases: 2.0(1.68) 3.1(1k)A. Known Fixed Releases: 92.2(1.105) 92.1(1.1733) 2.1(1.69).
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Firepower Extensible Operating System | =2.0\(1.68\) | |
Cisco Unified Computing System | =3.1\(1k\)a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-6598 is rated as high with a score of 6.7.
To mitigate CVE-2017-6598, update the Cisco Unified Computing System Manager and Cisco Firepower software to the latest versions provided by Cisco.
CVE-2017-6598 affects Cisco Unified Computing System Manager and Cisco Firepower 4100/9300 Series devices.
CVE-2017-6598 is a privilege escalation vulnerability that allows an authenticated local attacker to execute arbitrary commands.
CVE-2017-6598 can only be exploited by an authenticated local attacker, not remotely.