First published: Tue Jun 13 2017(Updated: )
A vulnerability in the feature-license management functionality of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass URL filters that have been configured for an affected device. More Information: CSCvb16413. Known Affected Releases: 6.0.1 6.1.0 6.2.0 6.2.1. Known Fixed Releases: 6.2.1 6.2.0.1 6.1.0.2.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Firepower Management Center | =6.0.1 | |
Cisco Firepower Management Center | =6.1.0 | |
Cisco Firepower Management Center | =6.2.0 | |
Cisco Firepower Management Center | =6.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6674 has been rated as a high severity vulnerability due to its potential impact on the integrity of URL filtering.
To remediate CVE-2017-6674, upgrade the Cisco Firepower System Software to a version that is not affected by this vulnerability.
CVE-2017-6674 affects Cisco Firepower System Software versions 6.0.1, 6.1.0, 6.2.0, and 6.2.1.
CVE-2017-6674 allows an unauthenticated, remote attacker to bypass configured URL filters on affected devices.
No, CVE-2017-6674 can be exploited by an unauthenticated attacker, making it particularly critical.