CVE-2017-3870 describes a medium-severity vulnerability in the URL filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA), impacting both virtual and hardware appliances configured with URL filters for email scanning. An unauthenticated, remote attacker could exploit this flaw to bypass configured URL filter rules, potentially allowing access to blocked content. The CVSSv3 score of 5.8 indicates a network-exploitable vulnerability with low attack complexity and a potential impact of low integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.5.3-069CPE matchmatch criteria | cpe:2.3:a:cisco:web_security_appliance:8.5.3-069:*:*:*:*:*:*:* | ||
9.1.1-074CPE matchmatch criteria | cpe:2.3:a:cisco:web_security_appliance:9.1.1-074:*:*:*:*:*:*:* | ||
9.1.2-010CPE matchmatch criteria | cpe:2.3:a:cisco:web_security_appliance:9.1.2-010:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.