Number: AV17-107
Date: 21 July 2017
Purpose
The purpose of this advisory is to bring attention to multiple Cisco security advisories.
Assessment
Cisco released multiple security updates to address vulnerabilities (high to medium) in the following products.
- Cisco ASR 5000 Series Aggregation Services Routers: GGSN Gateway Redirect Vulnerability
- Cisco ASR 5000 Series Aggregation Services Routers: Access Control List Security Bypass Vulnerability
- Cisco Prime Collaboration Provisioning Tool Web Portal: Cross-Site Scripting Vulnerability
- Cisco Web Security Appliance: Authenticated Command Injection and Privilege Escalation Vulnerability
- Cisco Web Security Appliance: Stored Cross-Site Scripting Vulnerability
- Cisco Web Security Appliance: Static Credentials Vulnerability
- Cisco Web Security Appliance: Administrative Interface Access Control Bypass Vulnerability
- Cisco Web Security Appliance: Command Injection and Privilege Escalation Vulnerability
CVE References: CVE-2017-6612, CVE-2017-6672, CVE-2017-6746, CVE-2017-6748, CVE-2017-6749, CVE-2017-6750, CVE-2017-6751, CVE-2017-6755
Suggested action
CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly
References
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-asr
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-asr1
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-pcpt
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-wsa1
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-wsa2
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-wsa3
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-wsa4
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-wsa5