CVE-2017-6751

A vulnerability in the web proxy functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to forward traffic from the web proxy interface of an affected device to the administrative management interface of an affected device, aka an Access Control Bypass Vulnerability. Affected Products: virtual and hardware versions of Cisco Web Security Appliance (WSA). More Information: CSCvd88863. Known Affected Releases: 10.1.0-204 9.0.0-485.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
VendorProductVersion
ciscoweb_security_appliance
9.0.0-162
ciscoweb_security_appliance
9.0.0-193
ciscoweb_security_appliance
9.0.0-485
ciscoweb_security_appliance
10.0.0-232
ciscoweb_security_appliance
10.0.0-233
ciscoweb_security_appliance
10.1.0-204
ciscoweb_security_virtual_appliance
9.0.0
ciscoweb_security_virtual_appliance
10.0.0
ciscoweb_security_virtual_appliance
10.1.0
ciscoweb_security_virtual_appliance
10.1.1
𝑥
= Vulnerable software versions