CVE-2017-6783 (CNNVD-201708-793)
中文标题:
多款Cisco产品SNMP polling 信息泄露漏洞
英文标题:
A vulnerability in SNMP polling for the Cisco Web Security Appliance (WSA), Email Security Appliance...
漏洞描述
中文描述:
Cisco Web Security Appliance(WSA)、Email Security Appliance(ESA)和Content Security Management Appliance(SMA)都是美国思科(Cisco)公司的产品。Cisco WSA是一套Web安全设备。ESA是一套电子邮件安全设备。Content SMA是一套内容安全管理设备。SNMP polling是其中的一个网络管理轮询(CPU决策如何提供周边设备服务的方式)组件。 多款Cisco产品中的SNMP polling存在信息泄露漏洞。远程攻击者可通过发送特制的SNMP轮询请求利用该漏洞获取证书信息。以下产品和版本受到影响:Cisco Web Security Appliance (WSA)10.0.0-230版本;Email Security Appliance (ESA)9.7.2-065版本;Content Security Management Appliance (SMA)10.1.0-037版本。
英文描述:
A vulnerability in SNMP polling for the Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to discover confidential information about the appliances that should be available only to an administrative user. The vulnerability occurs because the appliances do not protect confidential information at rest in response to Simple Network Management Protocol (SNMP) poll requests. An attacker could exploit this vulnerability by doing a crafted SNMP poll request to the targeted security appliance. An exploit could allow the attacker to discover confidential information that should be restricted, and the attacker could use this information to conduct additional reconnaissance. The attacker must know the configured SNMP community string to exploit this vulnerability. Cisco Bug IDs: CSCve26106, CSCve26202, CSCve26224. Known Affected Releases: 10.0.0-230 (Web Security Appliance), 9.7.2-065 (Email Security Appliance), and 10.1.0-037 (Content Security Management Appliance).
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco Systems, Inc. | Web Security Appliance (WSA) | 10.0.0-230 | - | - |
cpe:2.3:a:cisco_systems,_inc.:web_security_appliance_(wsa):10.0.0-230:*:*:*:*:*:*:*
|
| Cisco Systems, Inc. | Email Security Appliance (ESA) | 9.7.2-065 | - | - |
cpe:2.3:a:cisco_systems,_inc.:email_security_appliance_(esa):9.7.2-065:*:*:*:*:*:*:*
|
| Cisco Systems, Inc. | Content Security Management Appliance (SMA) | 10.1.0-037 | - | - |
cpe:2.3:a:cisco_systems,_inc.:content_security_management_appliance_(sma):10.1.0-037:*:*:*:*:*:*:*
|
| cisco | content_security_management_appliance | 10.1.0-037 | - | - |
cpe:2.3:a:cisco:content_security_management_appliance:10.1.0-037:*:*:*:*:*:*:*
|
| cisco | email_security_appliance | 9.7.2-065 | - | - |
cpe:2.3:a:cisco:email_security_appliance:9.7.2-065:*:*:*:*:*:*:*
|
| cisco | web_security_appliance | 10.0.0-230 | - | - |
cpe:2.3:a:cisco:web_security_appliance:10.0.0-230:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2017-6783 |
2025-11-11 15:19:31 | 2025-11-11 07:34:51 |
| NVD | nvd_CVE-2017-6783 |
2025-11-11 14:55:30 | 2025-11-11 07:43:28 |
| CNNVD | cnnvd_CNNVD-201708-793 |
2025-11-11 15:09:52 | 2025-11-11 07:53:14 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 信息泄露
- cnnvd_id: 未提取 -> CNNVD-201708-793
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 4.3
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 3 -> 6
- data_sources: ['cve'] -> ['cve', 'nvd']