Cisco Security Advisories · May 2017 — Cisco Security Advisories
37 advisories 38 CVEs 2 EXPLOITED

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2017-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.

Advisories

cisco-sa-20170517-fpwr

Cisco PSIRT2017-05-17

Cisco FirePOWER System Software SSL Logging Denial of Service Vulnerability

CVEs:CVE-2017-6632

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-220205 affected Cisco
CVRFPID-220206 affected Cisco
CVRFPID-223029 affected Cisco
CVRFPID-223031 affected Cisco
CVRFPID-223033 affected Cisco
CVRFPID-225827 affected Cisco
CVRFPID-226358 affected Cisco
CVRFPID-226359 affected Cisco
CVRFPID-226360 affected Cisco
CVRFPID-227125 affected Cisco
Upstream advisory

cisco-sa-20170517-nss

Cisco PSIRT2017-05-17

Cisco Nexus Series Switches CLI Command Injection Vulnerability

CVEs:CVE-2017-6649

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-208640 affected Cisco
CVRFPID-208806 affected Cisco
CVRFPID-209820 affected Cisco
CVRFPID-220733 affected Cisco
CVRFPID-220734 affected Cisco
CVRFPID-224614 affected Cisco
CVRFPID-224615 affected Cisco
Upstream advisory

cisco-sa-20170517-nss1

Cisco PSIRT2017-05-17

Cisco Nexus Series Switches Telnet CLI Command Injection Vulnerability

CVEs:CVE-2017-6650

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-208640 affected Cisco
CVRFPID-208806 affected Cisco
CVRFPID-209820 affected Cisco
CVRFPID-220733 affected Cisco
CVRFPID-220734 affected Cisco
CVRFPID-224614 affected Cisco
CVRFPID-224615 affected Cisco
Upstream advisory

cisco-sa-20170517-pcp3

Cisco PSIRT2017-05-17

Cisco Prime Collaboration Provisioning Directory Traversal Arbitrary File Deletion Vulnerability

CVEs:CVE-2017-6635

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-209583 affected Cisco
Upstream advisory

cisco-sa-20170517-pcp4

Cisco PSIRT2017-05-17

Cisco Prime Collaboration Provisioning Directory Traversal Information Disclosure Vulnerability

CVEs:CVE-2017-6636

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-209583 affected Cisco
Upstream advisory

cisco-sa-20170517-pcp5

Cisco PSIRT2017-05-17

Cisco Prime Collaboration Provisioning Directory Traversal Arbitrary File Deletion Vulnerability

CVEs:CVE-2017-6637

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-209583 affected Cisco
Upstream advisory

cisco-sa-20170517-rem5

Cisco PSIRT2017-05-17

Cisco Remote Expert Manager Virtual Temporary Directory Information Disclosure Vulnerability

CVEs:CVE-2017-6645

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-227169 affected Cisco
Upstream advisory

cisco-sa-20170503-cme

Cisco PSIRT2017-05-03

Cisco Aironet 1800, 2800, and 3800 Series Access Points Plug-and-Play Arbitrary Code Execution Vulnerability

CVEs:CVE-2017-3873

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-190024 affected Cisco
CVRFPID-230258 affected Cisco
Upstream advisory

cisco-sa-20170503-ctp

Cisco PSIRT2017-05-03

Cisco TelePresence ICMP Denial of Service Vulnerability

CVEs:CVE-2017-3825

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-192563 affected Cisco
CVRFPID-222445 affected Cisco
Upstream advisory

cisco-sa-20170503-ftd

Cisco PSIRT2017-05-03

Cisco Firepower Threat Defense and Cisco ASA with FirePOWER Module Denial of Service Vulnerability

CVEs:CVE-2017-6625

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-212171 affected Cisco
CVRFPID-212172 affected Cisco
CVRFPID-216309 affected Cisco
CVRFPID-220205 affected Cisco
CVRFPID-220206 affected Cisco
CVRFPID-223033 affected Cisco
CVRFPID-224894 affected Cisco
CVRFPID-225378 affected Cisco
CVRFPID-225827 affected Cisco
CVRFPID-226358 affected Cisco
CVRFPID-226359 affected Cisco
CVRFPID-226360 affected Cisco
CVRFPID-226361 affected Cisco
CVRFPID-226362 affected Cisco
Upstream advisory

cisco-sa-20170503-waas

Cisco PSIRT2017-05-03

Cisco Wide Area Application Services SMART-SSL Accelerator Denial of Service Vulnerability

CVEs:CVE-2017-6628

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-7367 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.