CVE-2017-6750
published 2017-07-25CVE-2017-6750: A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the…
PriorityP347high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
2.65%
84.0th percentile
A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the privileges of a limited user or an unauthenticated, remote attacker to authenticate to certain areas of the web GUI, aka a Static Credentials Vulnerability. Affected Products: virtual and hardware versions of Cisco Web Security Appliance (WSA). More Information: CSCve06124. Known Affected Releases: 10.1.0-204. Known Fixed Releases: 10.5.1-270.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance_static_credentials | — | — |
| cisco | web_security_virtual_appliance | — | — |
| cisco | web_security_virtual_appliance | — | — |
| cisco | web_security_virtual_appliance | — | — |
| cisco | web_security_virtual_appliance | — | — |
| cisco | web_security_virtual_appliance | — | — |
| cisco | web_security_virtual_appliance | — | — |
| cisco | web_security_virtual_appliance | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Web Security Appliance Static Credentials Vulnerability
vendor_cisco·2017-07-19·CVSS 5.3
CVE-2017-6750 [MEDIUM] CWE-255 Cisco Web Security Appliance Static Credentials Vulnerability
Cisco Web Security Appliance Static Credentials Vulnerability
A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the privileges of a limited user or an unauthenticated, remote attacker to authenticate to certain areas of the web GUI.
The vulnerability is due to a user account that has a default and static password. An attacker could exploit this vulnerability by connecting to the affected system using this default account. An exploit could allow the attacker to log in with the default credentials, allowing the attacker to view the system's serial number by using the CLI or to download reports by using the web interface.
There are no workarounds that address this vulnerability.
This advisory i
Cisco
Cisco Web Security Appliance Static Credentials Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-6750 Cisco Web Security Appliance Static Credentials Vulnerability
CVE-2017-6750: Cisco Web Security Appliance Static Credentials Vulnerability
A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the privileges of a limited user or an unauthenticated, remote attacker to authenticate to certain areas of the web GUI. The vulnerability is due to a user account that has a default and static password. An attacker could exploit this vulnerability by connecting to the affected system using this default account. An exploit could allow the attacker to log in with the default credentials, allowing the attacker to view the system's serial number by using the CLI or to download reports by using the web interface. There are no
CVSS: 3.0
CWE: CWE-255, CWE-255
Bug IDs: CSCve061
GHSA
GHSA-8hj4-pmp7-hg69: A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the
ghsa_unreviewed·2022-05-13
CVE-2017-6750 [HIGH] CWE-1188 GHSA-8hj4-pmp7-hg69: A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the
A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the privileges of a limited user or an unauthenticated, remote attacker to authenticate to certain areas of the web GUI, aka a Static Credentials Vulnerability. Affected Products: virtual and hardware versions of Cisco Web Security Appliance (WSA). More Information: CSCve06124. Known Affected Releases: 10.1.0-204. Known Fixed Releases: 10.5.1-270.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/99924http://www.securitytracker.com/id/1038958https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-wsa4http://www.securityfocus.com/bid/99924http://www.securitytracker.com/id/1038958https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-wsa4
2017-07-25
Published