CVE-2017-6750: High severity cisco web security appliance vulnerability
A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the privileges of a limited user or an unauthenticated, remote attacker to authenticate to certain areas of the web GUI, aka a Static Credentials Vulnerability. Affected Products: virtual and hardware versions of Cisco Web Security Appliance (WSA). More Information: CSCve06124. Known Affected Releases: 10.1.0-204. Known Fixed Releases: 10.5.1-270.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6750?
The severity of CVE-2017-6750 is considered high, as it allows unauthorized access to the web GUI of the Cisco Web Security Appliance.
How do I fix CVE-2017-6750?
To fix CVE-2017-6750, update the Cisco Web Security Appliance software to the latest version provided by Cisco.
What impact does CVE-2017-6750 have on my Cisco Web Security Appliance?
CVE-2017-6750 can allow an attacker to gain unauthorized access and potentially compromise the security of the device.
Who is affected by CVE-2017-6750?
CVE-2017-6750 affects multiple versions of the Cisco Web Security Appliance and Cisco Web Security Virtual Appliance.
Can I exploit CVE-2017-6750 remotely?
Yes, CVE-2017-6750 can be exploited by an unauthenticated remote attacker to authenticate to certain areas of the web GUI.