CVE-2017-6679
Summary
| CVE | CVE-2017-6679 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-12-01 17:29:00 UTC |
| Updated | 2026-06-22 13:52:20 UTC |
| Description | The Cisco Umbrella Virtual Appliance Version 2.0.3 and prior contained an undocumented encrypted remote support tunnel (SSH) which auto initiated from the customer's appliance to Cisco's SSH Hubs in the Umbrella datacenters. These tunnels were primarily leveraged for remote support and allowed for authorized/authenticated personnel from the Cisco Umbrella team to access the appliance remotely and obtain full control without explicit customer approval. To address this vulnerability, the Umbrella Virtual Appliance version 2.1.0 now requires explicit customer approval before an SSH tunnel from the VA to the Cisco terminating server can be established. |
Risk And Classification
Primary CVSS: v3.1 6.4 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Problem Types: NVD-CWE-noinfo | undocumented encrypted remote support tunnel
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 6.4 | MEDIUM | CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 6 | AV:L/AC:H/Au:S/C:C/I:C/A:C |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
HighPrivileges Required
HighUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
HighAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:H/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Umbrella Virtual Appliance | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | Cisco Umbrella Virtual Appliance Version 2.0.3 And Prior | affected Cisco Umbrella Virtual Appliance Version 2.0.3 and prior | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Umbrella Virtual Appliance Undocumented Support Tunnel Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | sec.cloudapps.cisco.com | Vendor Advisory |
| Virtual Appliance – Vulnerability due to always-on SSH Tunnel – RESOLVED – 2017-09-15 – Cisco Umbrella | af854a3a-2127-422b-91ae-364da2661108 | support.umbrella.com | Third Party Advisory |
| Cisco Umbrella Virtual Appliance CVE-2017-6679 Unauthorized Access Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Cisco Umbrella Virtual Appliance - Undocumented Support Tunnel (CVE-2017-6679) - Info-Sec.CA | af854a3a-2127-422b-91ae-364da2661108 | www.info-sec.ca | Third Party Advisory |
| On-Demand Tech Support SSH Tunnel for Virtual Appliances – Cisco Umbrella | af854a3a-2127-422b-91ae-364da2661108 | support.umbrella.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.