CVE-2017-6679
The Cisco Umbrella Virtual Appliance Version 2.0.3 and prior contained an undocumented encrypted remote support tunnel (SSH) which auto initiated from the customer's appliance to Cisco's SSH Hubs in the Umbrella datacenters. These tunnels were primarily leveraged for remote support and allowed for authorized/authenticated personnel from the Cisco Umbrella team to access the appliance remotely and obtain full control without explicit customer approval. To address this vulnerability, the Umbrella Virtual Appliance version 2.1.0 now requires explicit customer approval before an SSH tunnel from the VA to the Cisco terminating server can be established.
EPSS 0.11% · 29.5th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | Cisco Umbrella Virtual Appliance Version 2.0.3 and prior | Cisco Umbrella Virtual Appliance Version 2.0.3 and prior |
| cisco | umbrella | 0 |
Exploit Intelligence
- https://www.info-sec.ca/advisories/Cisco-Umbrella.html (circl)
- https://support.umbrella.com/hc/en-us/articles/115004752143-Virtual-Appliance-Vulnerability-due-to-always-on-SSH-Tunnel-RESOLVED-2017-09-15 (circl)
- 101567 (circl)
- https://support.umbrella.com/hc/en-us/articles/115004154423 (circl)
- 20230816 Cisco Umbrella Virtual Appliance Undocumented Support Tunnel Vulnerability (circl)
- Cisco Umbrella Virtual Appliance 2.0.3 Undocumented Support Tunnel Vulnerability (0day-today)
- Cisco Umbrella Virtual Appliance 2.0.3 Undocumented Support Tunnel Vulnerability (0day-today)
Timeline
- Oct 24, 2017 CVE Published
- Oct 24, 2017 PoC Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
References
- https://www.info-sec.ca/advisories/Cisco-Umbrella.html url
- https://support.umbrella.com/hc/en-us/articles/115004752143-Virtual-Appliance-Vulnerability-due-to-always-on-SSH-Tunnel-RESOLVED-2017-09-15 url
- 101567 vdb
- https://support.umbrella.com/hc/en-us/articles/115004154423 url
- 20230816 Cisco Umbrella Virtual Appliance Undocumented Support Tunnel Vulnerability vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-6679 advisory