CVE-2017-6783

Description

A vulnerability in SNMP polling for the Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to discover confidential information about the appliances that should be available only to an administrative user. The vulnerability occurs because the appliances do not protect confidential information at rest in response to Simple Network Management Protocol (SNMP) poll requests. An attacker could exploit this vulnerability by doing a crafted SNMP poll request to the targeted security appliance. An exploit could allow the attacker to discover confidential information that should be restricted, and the attacker could use this information to conduct additional reconnaissance. The attacker must know the configured SNMP community string to exploit this vulnerability. Cisco Bug IDs: CSCve26106, CSCve26202, CSCve26224. Known Affected Releases: 10.0.0-230 (Web Security Appliance), 9.7.2-065 (Email Security Appliance), and 10.1.0-037 (Content Security Management Appliance).

Category

4.3
CVSS
Severity: Medium
CVSS 3.0 •
CVSS 2.0 •
EPSS 0.28%
Vendor Advisory cisco.com
Affected: Cisco Systems, Inc. Web Security Appliance (WSA)
Affected: Cisco Systems, Inc. Email Security Appliance (ESA)
Affected: Cisco Systems, Inc. Content Security Management Appliance (SMA)
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2017-6783?
CVE-2017-6783 has been scored as a medium severity vulnerability.
How to fix CVE-2017-6783?
To fix CVE-2017-6783, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2017-6783 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2017-6783 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2017-6783?
CVE-2017-6783 affects Cisco Systems, Inc. Web Security Appliance (WSA), Cisco Systems, Inc. Email Security Appliance (ESA), Cisco Systems, Inc. Content Security Management Appliance (SMA).
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.