CVE-2017-6751: Cisco Web Security Appliance
High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.
A vulnerability in the web proxy functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to forward traffic from the web proxy interface of an affected device to the administrative management interface of an affected device, aka an Access Control Bypass Vulnerability. Affected Products: virtual and hardware versions of Cisco Web Security Appliance (WSA). More Information: CSCvd88863. Known Affected Releases: 10.1.0-204 9.0.0-485.
Affected products
- Cisco Web Security Appliance: version 9.0.0-162 only; version 9.0.0-193 only; version 9.0.0-485 only; version 10.0.0-232 only; version 10.0.0-233 only; version 10.1.0-204 only
- Cisco Web Security Virtual Appliance: version 9.0.0 only; version 10.0.0 only; version 10.1.0 only; version 10.1.1 only
Published 2017-07-25. Last modified 2026-06-17.