Information disclosure in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2017-6673
Published: June 8, 2017
Vulnerability identifier: #VU6988
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6673
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information.
The weakness exists in the Cisco Firepower Management Center logging function due to verbose output in HTTP log files. A remote attacker can retrieve the log files from an affected system and use the information to perform reconnaissance and conduct further attacks.
Successful exploitation of the vulnerability results in information disclosure.
The weakness exists in the Cisco Firepower Management Center logging function due to verbose output in HTTP log files. A remote attacker can retrieve the log files from an affected system and use the information to perform reconnaissance and conduct further attacks.
Successful exploitation of the vulnerability results in information disclosure.
Affected software
Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)
How to mitigate CVE-2017-6673
Update to version 6.2.0.