CVE Database
/

CVE-2017-6783

Back to search

CVE-2017-6783

Published: Aug 17, 2017

Modified: Sep 16, 2024

PUBLISHED

Description

A vulnerability in SNMP polling for the Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to discover confidential information about the appliances that should be available only to an administrative user. The vulnerability occurs because the appliances do not protect confidential information at rest in response to Simple Network Management Protocol (SNMP) poll requests. An attacker could exploit this vulnerability by doing a crafted SNMP poll request to the targeted security appliance. An exploit could allow the attacker to discover confidential information that should be restricted, and the attacker could use this information to conduct additional reconnaissance. The attacker must know the configured SNMP community string to exploit this vulnerability. Cisco Bug IDs: CSCve26106, CSCve26202, CSCve26224. Known Affected Releases: 10.0.0-230 (Web Security Appliance), 9.7.2-065 (Email Security Appliance), and 10.1.0-037 (Content Security Management Appliance).

VendorProductVersions

Cisco Systems, Inc.

Web Security Appliance (WSA)

affected
10.0.0-230

Cisco Systems, Inc.

Email Security Appliance (ESA)

affected
9.7.2-065

Cisco Systems, Inc.

Content Security Management Appliance (SMA)

affected
10.1.0-037

References

1039187
vdb-entry
x_refsource_SECTRACK
100387
vdb-entry
x_refsource_BID
1039186
vdb-entry
x_refsource_SECTRACK
1039188
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now