Security restrictions bypass in Cisco Web Security Appliance

Published: 2018-03-09 15:52:33
Severity Low
Patch available YES
Number of vulnerabilities 1
CVE ID CVE-2018-0087
CVSSv3 6.4 [CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C]
CWE ID CWE-284
Exploitation vector Network
Public exploit Not available
Vulnerable software Cisco Web Security Appliance
Vulnerable software versions Cisco Web Security Appliance 10.5.2-034
Vendor URL Cisco Systems, Inc

Security Advisory

1) Security restrictions bypass

Description

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The weakness exists in the FTP server due to incorrect FTP user credential validation. A remote attacker can use FTP to connect to the management IP address and log in to the FTP server of the Cisco WSA without having a valid password.

Remediation

Update to version 10.5.2-034.

External links

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180307-wsa

Back to List