CVE-2017-6602: OS Command Injection
A vulnerability in the CLI of Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb66189 CSCvb86775. Known Affected Releases: 2.0(1.68) 3.1(1k)A. Known Fixed Releases: 92.2(1.101) 92.1(1.1742) 92.1(1.1658) 2.1(1.38) 2.0(1.107) 2.0(1.87) 1.1(4.148) 1.1(4.138).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Unified Computing System (UCS) Manager CLI / Cisco Firepower 4100/9300 NGFW CLIto a version that resolves this vulnerability.Fixed in 92.2(1.101) - Upgrade
Upgrade
Cisco Unified Computing System (UCS) Manager CLI / Cisco Firepower 4100/9300 NGFW CLIto a version that resolves this vulnerability.Fixed in 92.1(1.1742) - Upgrade
Upgrade
Cisco Unified Computing System (UCS) Manager CLI / Cisco Firepower 4100/9300 NGFW CLIto a version that resolves this vulnerability.Fixed in 92.1(1.1658) - Upgrade
Upgrade
Cisco Unified Computing System (UCS) Manager CLI / Cisco Firepower 4100/9300 NGFW CLIto a version that resolves this vulnerability.Fixed in 2.1(1.38) - Upgrade
Upgrade
Cisco Unified Computing System (UCS) Manager CLI / Cisco Firepower 4100/9300 NGFW CLIto a version that resolves this vulnerability.Fixed in 2.0(1.107) - Upgrade
Upgrade
Cisco Unified Computing System (UCS) Manager CLI / Cisco Firepower 4100/9300 NGFW CLIto a version that resolves this vulnerability.Fixed in 2.0(1.87) - Upgrade
Upgrade
Cisco Unified Computing System (UCS) Manager CLI / Cisco Firepower 4100/9300 NGFW CLIto a version that resolves this vulnerability.Fixed in 1.1(4.148) - Upgrade
Upgrade
Cisco Unified Computing System (UCS) Manager CLI / Cisco Firepower 4100/9300 NGFW CLIto a version that resolves this vulnerability.Fixed in 1.1(4.138) - Compensating control
If immediate upgrade is not possible, treat CLI access as high-risk for authenticated local attackers referenced in CSCvb66189 and CSCvb86775 and restrict local/management CLI access to trusted users/sources where feasible.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6602?
CVE-2017-6602 is classified as a high-severity vulnerability that could lead to command injection attacks.
How do I fix CVE-2017-6602?
To fix CVE-2017-6602, update the affected Cisco Unified Computing System software or Cisco Firepower Extensible Operating System to the latest version provided by Cisco.
Which Cisco products are affected by CVE-2017-6602?
CVE-2017-6602 affects the Cisco Unified Computing System Manager and the Cisco Firepower 4100 and 9300 Series appliances.
Can CVE-2017-6602 be exploited remotely?
No, CVE-2017-6602 can only be exploited by an authenticated local attacker.
What types of attacks can result from CVE-2017-6602?
CVE-2017-6602 can allow an attacker to execute arbitrary commands through a command injection attack.