445
VMScore

CVE-2017-6750

Published: 25/07/2017 Updated: 03/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local malicious user to log in to the device with the privileges of a limited user or an unauthenticated, remote malicious user to authenticate to certain areas of the web GUI, aka a Static Credentials Vulnerability. Affected Products: virtual and hardware versions of Cisco Web Security Appliance (WSA). More Information: CSCve06124. Known Affected Releases: 10.1.0-204. Known Fixed Releases: 10.5.1-270.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco web security appliance 10.1.1-235

cisco web security appliance 10.5.0-358

cisco web security appliance 10.1.0-204

cisco web security appliance 10.1.1-234

cisco web security appliance 10.0.0-233

cisco web security appliance 10.1.1-230

cisco web security appliance 10.0.0-232

cisco web security virtual appliance 10.0.0

cisco web security appliance 10.1.0

cisco web security virtual appliance 10.0_base

cisco web security virtual appliance 10.5.1

cisco web security virtual appliance 10.5_base

cisco web security appliance 10.5.0

cisco web security appliance 10.0_base

cisco web security virtual appliance 10.1.0

cisco web security virtual appliance 10.1.1

cisco web security virtual appliance 10.1_base

Vendor Advisories

A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the privileges of a limited user or an unauthenticated, remote attacker to authenticate to certain areas of the web GUI The vulnerability is due to a user account that has a default and static password ...