PatchSiren cyber security CVE debrief
CVE-2017-3822 Cisco CVE debrief
CVE-2017-3822 is a Cisco Firepower Threat Defense logging subsystem issue that can let an unauthenticated remote attacker add arbitrary entries to the audit log on affected Firepower Device Manager-enabled appliances. The vulnerability is rated medium severity and was addressed in Cisco Firepower Threat Defense Software 6.2.0.
- Vendor
- Cisco
- Product
- Firepower Threat Defense
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-03
- Original CVE updated
- 2026-08-11
- Advisory published
- 2017-02-03
- Advisory updated
- 2026-08-11
Who should care
Security teams operating Cisco Firepower Threat Defense 6.1.x appliances, especially ASA5506-X, ASA5506W-X, ASA5506H-X, ASA5508-X, ASA5516-X, ASA5512-X, ASA5515-X, ASA5525-X, ASA5545-X, and ASA5555-X deployments with Firepower Device Manager enabled. Logging, audit, and compliance owners should also care because the issue affects audit-log integrity.
Technical summary
NVD describes the flaw as a remote, network-reachable issue with no privileges or user interaction required, where the impact is limited to integrity of the audit log. The NVD CVSS v3.0 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N, and the weakness classification is CWE-20. The affected CPE entry in the source corpus maps to Cisco Firepower Threat Defense 6.1.0, with Cisco's advisory reference indicating the broader 6.1.x product line when Firepower Device Manager is enabled.
Defensive priority
Medium priority. The issue does not indicate confidentiality or availability impact, but it can undermine trust in audit records and complicate detection, investigation, and compliance workflows.
Recommended defensive actions
- Upgrade affected Cisco Firepower Threat Defense deployments to the fixed release noted in the source corpus: 6.2.0.
- Verify whether Firepower Device Manager is enabled on any vulnerable ASA5506-X/5506W-X/5506H-X/5508-X/5516-X/5512-X/5515-X/5525-X/5545-X/5555-X appliances running 6.1.x.
- Review audit-log integrity controls and alerting to detect unexpected or inconsistent log entries.
- Use the Cisco vendor advisory and NVD record to confirm exposure scope against your environment.
- Prioritize remediation where audit logs are used for incident response, compliance evidence, or security monitoring.
Evidence notes
The source corpus identifies CVE-2017-3822 as affecting Cisco Firepower Threat Defense Software 6.1.x with Firepower Device Manager enabled on specific ASA models, and states that 6.2.0 is the known fixed release. NVD metadata classifies the issue as CWE-20 and provides the CVSS v3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N. References in the corpus include Cisco's vendor advisory URL and third-party advisory entries.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-3822 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-3822
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-3822 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3822
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170201-fpw2
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.