CVE-2017-6679: Medium severity Cisco Umbrella vulnerability
The Cisco Umbrella Virtual Appliance Version 2.0.3 and prior contained an undocumented encrypted remote support tunnel (SSH) which auto initiated from the customer's appliance to Cisco's SSH Hubs in the Umbrella datacenters. These tunnels were primarily leveraged for remote support and allowed for authorized/authenticated personnel from the Cisco Umbrella team to access the appliance remotely and obtain full control without explicit customer approval. To address this vulnerability, the Umbrella Virtual Appliance version 2.1.0 now requires explicit customer approval before an SSH tunnel from the VA to the Cisco terminating server can be established.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Umbrella Virtual Applianceto a version that resolves this vulnerability.Fixed in 2.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6679?
CVE-2017-6679 is categorized as a medium severity vulnerability due to the potential for unauthorized access through an encrypted remote support tunnel.
How do I fix CVE-2017-6679?
To remediate CVE-2017-6679, upgrade to Cisco Umbrella Virtual Appliance version 2.0.4 or later.
Who is affected by CVE-2017-6679?
CVE-2017-6679 affects all versions of Cisco Umbrella Virtual Appliance up to and including 2.0.3.
What are the risks associated with CVE-2017-6679?
The risks include potential unauthorized access to the system through the undetected remote support tunnel.
Is there a workaround for CVE-2017-6679?
There is no documented workaround for CVE-2017-6679, so upgrading the software is strongly recommended.