First published: Tue Jul 25 2017(Updated: )
A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the privileges of a limited user or an unauthenticated, remote attacker to authenticate to certain areas of the web GUI, aka a Static Credentials Vulnerability. Affected Products: virtual and hardware versions of Cisco Web Security Appliance (WSA). More Information: CSCve06124. Known Affected Releases: 10.1.0-204. Known Fixed Releases: 10.5.1-270.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Web Security Appliance | =10.0.0-232 | |
Cisco Web Security Appliance | =10.0.0-233 | |
Cisco Web Security Appliance | =10.0_base | |
Cisco Web Security Appliance | =10.1.0 | |
Cisco Web Security Appliance | =10.1.0-204 | |
Cisco Web Security Appliance | =10.1.1-230 | |
Cisco Web Security Appliance | =10.1.1-234 | |
Cisco Web Security Appliance | =10.1.1-235 | |
Cisco Web Security Appliance | =10.5.0 | |
Cisco Web Security Appliance | =10.5.0-358 | |
Cisco Web Security Virtual Appliance | =10.0.0 | |
Cisco Web Security Virtual Appliance | =10.0_base | |
Cisco Web Security Virtual Appliance | =10.1.0 | |
Cisco Web Security Virtual Appliance | =10.1.1 | |
Cisco Web Security Virtual Appliance | =10.1_base | |
Cisco Web Security Virtual Appliance | =10.5.1 | |
Cisco Web Security Virtual Appliance | =10.5_base |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-6750 is considered high, as it allows unauthorized access to the web GUI of the Cisco Web Security Appliance.
To fix CVE-2017-6750, update the Cisco Web Security Appliance software to the latest version provided by Cisco.
CVE-2017-6750 can allow an attacker to gain unauthorized access and potentially compromise the security of the device.
CVE-2017-6750 affects multiple versions of the Cisco Web Security Appliance and Cisco Web Security Virtual Appliance.
Yes, CVE-2017-6750 can be exploited by an unauthenticated remote attacker to authenticate to certain areas of the web GUI.