CVE-2017-6661: XSS
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device, aka Message Tracking XSS. More Information: CSCvd30805 CSCvd34861. Known Affected Releases: 10.0.0-203 10.1.0-049.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6661?
CVE-2017-6661 is rated as a medium-severity vulnerability due to its ability to allow cross-site scripting attacks.
How can I fix CVE-2017-6661?
To fix CVE-2017-6661, update your Cisco Email Security Appliance or Cisco Content Security Management Appliance to the latest patched version.
What type of attack is possible with CVE-2017-6661?
CVE-2017-6661 allows an unauthenticated remote attacker to perform a cross-site scripting (XSS) attack.
Which Cisco products are affected by CVE-2017-6661?
CVE-2017-6661 affects the Cisco Email Security Appliance and Cisco Content Security Management Appliance versions 10.0.0-203 and 10.1.0-049.
Is user authentication required to exploit CVE-2017-6661?
No, user authentication is not required to exploit CVE-2017-6661, making it particularly concerning.