7.2

CVE-2017-6748

A vulnerability in the CLI parser of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. The attacker must authenticate with valid operator-level or administrator-level credentials. Affected Products: virtual and hardware versions of Cisco Web Security Appliance (WSA). More Information: CSCvd88855. Known Affected Releases: 10.1.0-204. Known Fixed Releases: 10.5.1-270 10.1.1-234.

Data is provided by the National Vulnerability Database (NVD)
CiscoWeb Security Appliance Version10.0.0-232
CiscoWeb Security Appliance Version10.0.0-233
CiscoWeb Security Appliance Version10.0_base
CiscoWeb Security Appliance Version10.1.0
CiscoWeb Security Appliance Version10.1.0-204
CiscoWeb Security Appliance Version10.1.1-230
CiscoWeb Security Appliance Version10.5.0
CiscoWeb Security Appliance Version10.5.0-358
CiscoWeb Security Appliance Version11.0.0
CiscoWeb Security Appliance Version11.0.0-613
CiscoWeb Security Virtual Appliance Version10.0_base
CiscoWeb Security Virtual Appliance Version10.1_base
CiscoWeb Security Virtual Appliance Version10.5_base
CiscoWeb Security Virtual Appliance Version11.0_base
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.32% 0.515
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.