Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-6746


A vulnerability in the web interface of the Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. The attacker must authenticate with valid administrator credentials. Affected Products: Cisco AsyncOS Software 10.0 and later for WSA on both virtual and hardware appliances. More Information: CSCvd88862. Known Affected Releases: 10.1.0-204. Known Fixed Releases: 10.5.1-270 10.1.1-235.


Published

2017-07-25T19:29:00.240

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 7.2 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco web_security_appliance 10.0.0-233 Yes
Application cisco web_security_appliance 10.0_base Yes
Application cisco web_security_appliance 10.1.0 Yes
Application cisco web_security_appliance 10.1.0-204 Yes
Application cisco web_security_appliance 10.1.1-230 Yes
Application cisco web_security_appliance 10.1.1-234 Yes
Application cisco web_security_appliance 10.5.0 Yes
Application cisco web_security_appliance 10.5.0-358 Yes
Application cisco web_security_appliance 11.0.0 Yes
Application cisco web_security_appliance 11.0.0-613 Yes
Application cisco web_security_appliance 11.0.0-641 Yes

References