CVE-2017-6749: Cisco Web Security Appliance

Medium severity, CVSS 5.4. EPSS: 1.2% chance of exploitation in the next 30 days.

A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. Affected Products: virtual and hardware versions of Cisco Web Security Appliance (WSA). More Information: CSCvd88865. Known Affected Releases: 10.1.0-204.

Affected products

  • Cisco Web Security Appliance: version 10.0.0-232 only; version 10.0.0-233 only; version 10.0_base only; version 10.1.0 only; version 10.1.0-204 only; version 10.1.1-230 only; …
  • Cisco Web Security Virtual Appliance: version 10.0.0 only; version 10.0_base only; version 10.1.0 only; version 10.1.1 only; version 10.1_base only; version 10.5.1 only; …

Published 2017-07-25. Last modified 2026-06-17.