Encrypted Remote Support Tunnel in Cisco Umbrella Virtual Appliance
CVE-2017-6679
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 1 December 2017
What is CVE-2017-6679?
The Cisco Umbrella Virtual Appliance, prior to version 2.1.0, featured an undocumented encrypted SSH tunnel that automatically initiated from the appliance to Cisco's SSH Hubs in Umbrella datacenters. This functionality permitted remote support personnel from Cisco to access the appliance without the explicit consent of the customer, thus raising serious security concerns. In response, the updated version now mandates explicit customer approval before establishing an SSH connection from the appliance to Cisco's servers, enhancing customer control over remote access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Umbrella Virtual Appliance Version 2.0.3 and prior Cisco Umbrella Virtual Appliance Version 2.0.3 and prior
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved