CVE-2017-6597
A vulnerability in the local-mgmt CLI command of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.81%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability in the local-mgmt CLI command of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61394 CSCvb86816. Known Affected Releases: 2.0(1.68) 3.1(1k)A. Known Fixed Releases: 92.2(1.101) 92.1(1.1658) 2.0(1.115).
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.81% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- cisco/unified computing system · cisco/firepower extensible operating system
- Source
- psirt@cisco.com
References
- http://www.securityfocus.com/bid/97476Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038195
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-cliVendor Advisory
- http://www.securityfocus.com/bid/97476Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038195
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-cliVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.