CVE Database
/

CVE-2017-6748

Back to search

CVE-2017-6748

Published: Jul 25, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

A vulnerability in the CLI parser of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. The attacker must authenticate with valid operator-level or administrator-level credentials. Affected Products: virtual and hardware versions of Cisco Web Security Appliance (WSA). More Information: CSCvd88855. Known Affected Releases: 10.1.0-204. Known Fixed Releases: 10.5.1-270 10.1.1-234.

VendorProductVersions

n/a

Cisco Web Security Appliance

affected
Cisco Web Security Appliance

References

1038956
vdb-entry
x_refsource_SECTRACK
99918
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now