CVE-2017-6716: XSS
A vulnerability in the web framework code of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system. Affected Products: Cisco Firepower Management Center Software Releases prior to 6.0.0.0. More Information: CSCuy88785. Known Affected Releases: 5.4.1.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6716?
CVE-2017-6716 has a severity score of 6.1, indicating it is of medium severity.
How do I fix CVE-2017-6716?
To fix CVE-2017-6716, update to the latest version of Cisco Firepower Management Center Software as specified in the advisory.
What type of attack can CVE-2017-6716 allow?
CVE-2017-6716 could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack.
Which Cisco Firepower Management Center versions are affected by CVE-2017-6716?
Versions 5.3.1.7 and 5.4.0 through 5.4.1.9 of Cisco Firepower Management Center are affected by CVE-2017-6716.
Who is at risk due to CVE-2017-6716?
Users of the web interface of affected Cisco Firepower Management Center systems are at risk due to CVE-2017-6716.