First published: Tue Jul 04 2017(Updated: )
A vulnerability in the web framework code of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system. Affected Products: Cisco Firepower Management Center Software Releases prior to 6.0.0.0. More Information: CSCuy88785. Known Affected Releases: 5.4.1.6.
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure Firewall Management Center | =5.3.1.7 | |
Cisco Secure Firewall Management Center | =5.4.0 | |
Cisco Secure Firewall Management Center | =5.4.0.2 | |
Cisco Secure Firewall Management Center | =5.4.1 | |
Cisco Secure Firewall Management Center | =5.4.1.1 | |
Cisco Secure Firewall Management Center | =5.4.1.2 | |
Cisco Secure Firewall Management Center | =5.4.1.3 | |
Cisco Secure Firewall Management Center | =5.4.1.4 | |
Cisco Secure Firewall Management Center | =5.4.1.5 | |
Cisco Secure Firewall Management Center | =5.4.1.6 | |
Cisco Secure Firewall Management Center | =5.4.1.9 | |
Cisco Firepower Management Center Software | =5.3.1.7 | |
Cisco Firepower Management Center Software | =5.4.0 | |
Cisco Firepower Management Center Software | =5.4.0.2 | |
Cisco Firepower Management Center Software | =5.4.1 | |
Cisco Firepower Management Center Software | =5.4.1.1 | |
Cisco Firepower Management Center Software | =5.4.1.2 | |
Cisco Firepower Management Center Software | =5.4.1.3 | |
Cisco Firepower Management Center Software | =5.4.1.4 | |
Cisco Firepower Management Center Software | =5.4.1.5 | |
Cisco Firepower Management Center Software | =5.4.1.6 | |
Cisco Firepower Management Center Software | =5.4.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6716 has a severity score of 6.1, indicating it is of medium severity.
To fix CVE-2017-6716, update to the latest version of Cisco Firepower Management Center Software as specified in the advisory.
CVE-2017-6716 could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack.
Versions 5.3.1.7 and 5.4.0 through 5.4.1.9 of Cisco Firepower Management Center are affected by CVE-2017-6716.
Users of the web interface of affected Cisco Firepower Management Center systems are at risk due to CVE-2017-6716.