
CVE-2017-6766
https://notcve.org/view.php?id=CVE-2017-6766
07 Aug 2017 — A vulnerability in the Secure Sockets Layer (SSL) Decryption and Inspection feature of Cisco Firepower System Software 5.4.0, 5.4.1, 6.0.0, 6.1.0, 6.2.0, 6.2.1, and 6.2.2 could allow an unauthenticated, remote attacker to bypass the SSL policy for decrypting and inspecting traffic on an affected system. The vulnerability is due to unexpected interaction with Known Key and Decrypt and Resign configuration settings of SSL policies when the affected software receives unexpected SSL packet headers. An attacker ... • https://quickview.cloudapps.cisco.com/quickview/bug/CSCve12652 • CWE-310: Cryptographic Issues •

CVE-2017-6735
https://notcve.org/view.php?id=CVE-2017-6735
10 Jul 2017 — A vulnerability in the backup and restore functionality of Cisco FireSIGHT System Software could allow an authenticated, local attacker to execute arbitrary code on a targeted system. More Information: CSCvc91092. Known Affected Releases: 6.2.0 6.2.1. Una vulnerabilidad en la funcionalidad backup y restore de Cisco FireSIGHT System Software, podría permitir a un atacante local autenticado ejecutar código arbitrario en un sistema destino. Más información: CSCvc91092. • http://www.securityfocus.com/bid/99460 • CWE-20: Improper Input Validation •