Cisco Bug: CSCzv85726 - Authenticated command injection vulnerabilities on GUI pages
Aug 06, 2018
- Cisco Web Security Appliance
Known Affected Releases
5.7.1-000 6.3.8-008 7.1.3-MR-000 7.1.4-000 7.1.4-sandbox-000 7.5.0-833 7.5.0-MR-000 7.5.1-000 7.5.2-000 7.7.0-000 7.7.5-000 8.0.0-000
Symptom: Summary Cisco IronPort AsyncOS Software for Cisco Web Security Appliance is affected by the following vulnerabilities: Two authenticated command injection vulnerabilities Management GUI Denial of Service Vulnerability Conditions: These vulnerabilities are independent of each other; a release that is affected by one of the vulnerabilities may not be affected by the others. Successful exploitation of any of the two command injection vulnerabilities could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system with elevated privileges. Successful exploitation of the Management GUI Denial of Service Vulnerability could cause several critical processes to become unresponsive and make the affected system unstable.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.
Bug Details Include
- Full Description (including symptoms, conditions and workarounds)
- Known Fixed Releases
- Related Community Discussions
- Number of Related Support Cases