Lucene search

K
ciscoCiscoCISCO-SA-20170719-WSA4
HistoryJul 19, 2017 - 4:00 p.m.

Cisco Web Security Appliance Static Credentials Vulnerability

2017-07-1916:00:00
tools.cisco.com
16

EPSS

0.001

Percentile

47.5%

A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the privileges of a limited user or an unauthenticated, remote attacker to authenticate to certain areas of the web GUI.

The vulnerability is due to a user account that has a default and static password. An attacker could exploit this vulnerability by connecting to the affected system using this default account. An exploit could allow the attacker to log in with the default credentials, allowing the attacker to view the system’s serial number by using the CLI or to download reports by using the web interface.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-wsa4 [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-wsa4”]

Affected configurations

Vulners
Node
ciscoweb_security_appliance_\(wsa\)Matchany
OR
ciscoweb_security_virtual_applianceMatchany
OR
ciscoweb_security_appliance_\(wsa\)Matchany
OR
ciscoweb_security_virtual_applianceMatchany
VendorProductVersionCPE
ciscoweb_security_appliance_\(wsa\)anycpe:2.3:a:cisco:web_security_appliance_\(wsa\):any:*:*:*:*:*:*:*
ciscoweb_security_virtual_applianceanycpe:2.3:a:cisco:web_security_virtual_appliance:any:*:*:*:*:*:*:*

EPSS

0.001

Percentile

47.5%

Related for CISCO-SA-20170719-WSA4