Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-3870

Опубликовано: 17 мар. 2017
Источник: nvd
CVSS3: 5.8
CVSS2: 5
EPSS Низкий

Описание

A vulnerability in the URL filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured URL filter rule. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA), both virtual and hardware appliances, that are configured with URL filters for email scanning. More Information: CSCvc69700. Known Affected Releases: 8.5.3-069 9.1.1-074 9.1.2-010.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:web_security_appliance:8.5.3-069:*:*:*:*:*:*:*
cpe:2.3:a:cisco:web_security_appliance:9.1.1-074:*:*:*:*:*:*:*
cpe:2.3:a:cisco:web_security_appliance:9.1.2-010:*:*:*:*:*:*:*

EPSS

Процентиль: 48%
0.00254
Низкий

5.8 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 5.8
github
больше 3 лет назад

A vulnerability in the URL filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured URL filter rule. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA), both virtual and hardware appliances, that are configured with URL filters for email scanning. More Information: CSCvc69700. Known Affected Releases: 8.5.3-069 9.1.1-074 9.1.2-010.

EPSS

Процентиль: 48%
0.00254
Низкий

5.8 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-119