Vulnslist

find the latest Cisco vulnerabilities

Cisco Security Appliances SNMP Polling Information Disclosure Vulnerability

cisco-sa-20170816-csa · Medium · Published · Updated

A vulnerability in SNMP polling for the Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to discover confidential information about the appliances that should be available only to an administrative user. The vulnerability occurs because the appliances do not protect confidential information at rest in response to Simple Network Management Protocol (SNMP) poll requests. An attacker could exploit this vulnerability by doing a crafted SNMP poll request to the targeted security appliance. An exploit could allow the attacker to discover confidential information that should be restricted, and the attacker could use this information to conduct additional reconnaissance. The attacker must know the configured SNMP community string to exploit this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170816-csa

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2017-6783
Cisco Bug IDsCSCve26106, CSCve26202, CSCve26224
CVSS ScoreBase 4.3
Base 4.3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Web Security Appliance (WSA), Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), Cisco Secure Email, Cisco Secure Email and Web Manager, Cisco Secure Web Appliance

Related Products

Product CVE Evidence
Cisco Web Security Appliance (WSA) CVE-2017-6783 Cisco OpenVuln
Cisco Secure Web Appliance CVE-2017-6783 Cisco OpenVuln
Cisco Secure Email and Web Manager CVE-2017-6783 Cisco OpenVuln
Cisco Secure Email CVE-2017-6783 Cisco OpenVuln
Cisco Email Security Appliance (ESA) CVE-2017-6783 Cisco OpenVuln
Cisco Content Security Management Appliance (SMA) CVE-2017-6783 Cisco OpenVuln