First published: Tue Jul 04 2017(Updated: )
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. More Information: CSCvc38801. Known Affected Releases: 6.0.1.3 6.2.1. Known Fixed Releases: 6.2.1.
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure Firewall Management Center | =5.4.0 | |
Cisco Secure Firewall Management Center | =5.4.0.2 | |
Cisco Secure Firewall Management Center | =5.4.1 | |
Cisco Secure Firewall Management Center | =5.4.1.1 | |
Cisco Secure Firewall Management Center | =5.4.1.2 | |
Cisco Secure Firewall Management Center | =5.4.1.3 | |
Cisco Secure Firewall Management Center | =5.4.1.4 | |
Cisco Secure Firewall Management Center | =5.4.1.5 | |
Cisco Secure Firewall Management Center | =5.4.1.6 | |
Cisco Secure Firewall Management Center | =5.4.1.9 | |
Cisco Secure Firewall Management Center | =5.4_base | |
Cisco Secure Firewall Management Center | =6.0.0 | |
Cisco Secure Firewall Management Center | =6.0.0.0 | |
Cisco Secure Firewall Management Center | =6.0.0.1 | |
Cisco Secure Firewall Management Center | =6.0.1 | |
Cisco Secure Firewall Management Center | =6.0.1.1 | |
Cisco Secure Firewall Management Center | =6.0.1.3 | |
Cisco Secure Firewall Management Center | =6.0_base | |
Cisco Secure Firewall Management Center | =6.1.0 | |
Cisco Secure Firewall Management Center | =6.1.0.2 | |
Cisco Secure Firewall Management Center | =6.2.0 | |
Cisco Secure Firewall Management Center | =6.2.0.2 | |
Cisco Firepower Management Center Software | =5.4.0 | |
Cisco Firepower Management Center Software | =5.4.0.2 | |
Cisco Firepower Management Center Software | =5.4.1 | |
Cisco Firepower Management Center Software | =5.4.1.1 | |
Cisco Firepower Management Center Software | =5.4.1.2 | |
Cisco Firepower Management Center Software | =5.4.1.3 | |
Cisco Firepower Management Center Software | =5.4.1.4 | |
Cisco Firepower Management Center Software | =5.4.1.5 | |
Cisco Firepower Management Center Software | =5.4.1.6 | |
Cisco Firepower Management Center Software | =5.4.1.9 | |
Cisco Firepower Management Center Software | =5.4_base | |
Cisco Firepower Management Center Software | =6.0.0 | |
Cisco Firepower Management Center Software | =6.0.0.0 | |
Cisco Firepower Management Center Software | =6.0.0.1 | |
Cisco Firepower Management Center Software | =6.0.1 | |
Cisco Firepower Management Center Software | =6.0.1.1 | |
Cisco Firepower Management Center Software | =6.0.1.3 | |
Cisco Firepower Management Center Software | =6.0_base | |
Cisco Firepower Management Center Software | =6.1.0 | |
Cisco Firepower Management Center Software | =6.1.0.2 | |
Cisco Firepower Management Center Software | =6.2.0 | |
Cisco Firepower Management Center Software | =6.2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6717 has a medium severity rating, allowing an authenticated attacker to exploit the vulnerability.
To fix CVE-2017-6717, upgrade to one of the known fixed releases provided by Cisco.
CVE-2017-6717 affects specific versions of Cisco Secure Firewall Management Center and Cisco Firepower Management Center.
Yes, CVE-2017-6717 can allow attackers to perform cross-site scripting (XSS) attacks potentially leading to data exposure.
If your organization uses the affected Cisco products, CVE-2017-6717 is relevant and should not be overlooked.