Information disclosure in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2017-6673

 

Information disclosure in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2017-6673

Published: June 8, 2017


Vulnerability identifier: #VU6988
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6673
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information.

The weakness exists in the Cisco Firepower Management Center logging function due to verbose output in HTTP log files. A remote attacker can retrieve the log files from an affected system and use the information to perform reconnaissance and conduct further attacks.

Successful exploitation of the vulnerability results in information disclosure.

Affected software

Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)

How to mitigate CVE-2017-6673

Update to version 6.2.0.


External References

Related Security Bulletins