CVE-2017-6674: Input Validation
A vulnerability in the feature-license management functionality of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass URL filters that have been configured for an affected device. More Information: CSCvb16413. Known Affected Releases: 6.0.1 6.1.0 6.2.0 6.2.1. Known Fixed Releases: 6.2.1 6.2.0.1 6.1.0.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6674?
CVE-2017-6674 has been rated as a high severity vulnerability due to its potential impact on the integrity of URL filtering.
How do I fix CVE-2017-6674?
To remediate CVE-2017-6674, upgrade the Cisco Firepower System Software to a version that is not affected by this vulnerability.
Which versions of Cisco Firepower System Software are affected by CVE-2017-6674?
CVE-2017-6674 affects Cisco Firepower System Software versions 6.0.1, 6.1.0, 6.2.0, and 6.2.1.
What type of attack does CVE-2017-6674 enable?
CVE-2017-6674 allows an unauthenticated, remote attacker to bypass configured URL filters on affected devices.
Is authentication required to exploit CVE-2017-6674?
No, CVE-2017-6674 can be exploited by an unauthenticated attacker, making it particularly critical.