3.5
CVSSv2

CVE-2017-6749

Published: 25/07/2017 Updated: 31/07/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an authenticated, remote malicious user to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. Affected Products: virtual and hardware versions of Cisco Web Security Appliance (WSA). More Information: CSCvd88865. Known Affected Releases: 10.1.0-204.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco web security virtual appliance 10.0_base

cisco web security virtual appliance 10.1.0

cisco web security virtual appliance 10.5.1

cisco web security appliance 10.1.1-230

cisco web security appliance 10.5.0

cisco web security appliance 10.5.1-270

cisco web security virtual appliance 10.1_base

cisco web security appliance 10.5.0-358

cisco web security appliance 10.1.1-235

cisco web security virtual appliance 10.0.0

cisco web security virtual appliance 10.5_base

cisco web security appliance 10.1.1-234

cisco web security appliance 10.0_base

cisco web security appliance 10.0.0-232

cisco web security appliance 10.1.0

cisco web security virtual appliance 10.1.1

cisco web security appliance 10.1.0-204

cisco web security appliance 10.0.0-233

Vendor Advisories

A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device The vulnerability is due to insufficient validation of user-supplied input by the ...