PatchSiren cyber security CVE debrief
CVE-2017-3847 Cisco CVE debrief
CVE-2017-3847 is a medium-severity cross-site scripting (XSS) issue in the web framework of Cisco Firepower Management Center. According to the CVE and NVD record, an authenticated remote attacker could trigger XSS against a user of the web interface. The vulnerability is associated with Cisco Firepower Management Center 6.2.1 and carries a CVSS v3.0 score of 5.4 (AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
- Vendor
- Cisco
- Product
- Secure Firewall Management Center
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-22
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-22
- Advisory updated
- 2026-05-13
Who should care
Organizations running Cisco Firepower Management Center 6.2.1, especially teams that rely on the FMC web interface for administration and monitoring. Security and platform administrators should review the Cisco advisory and NVD record to confirm whether their deployment is affected and what remediation guidance applies.
Technical summary
The supplied sources describe a web-framework XSS condition in Cisco Firepower Management Center. The attack requires authentication and user interaction, and the CVSS vector shows network attackability with low complexity, limited privileges, and scope change. The NVD record maps the weakness to CWE-79 and identifies Cisco Firepower Management Center 6.2.1 as the affected release in the supplied corpus.
Defensive priority
Medium. Prioritize remediation if Cisco Firepower Management Center 6.2.1 is in production or exposed to a broad set of administrative users, because the flaw can be used to execute script in a victim user's browser session through the web interface.
Recommended defensive actions
- Confirm whether Cisco Firepower Management Center 6.2.1 is deployed in your environment.
- Review the Cisco Security Advisory for Cisco Firepower Management Center referenced in the official sources.
- Check the NVD entry for the current vulnerability status and any linked remediation details.
- Limit access to the FMC web interface to trusted administrative users and networks while remediation is assessed.
- Monitor for suspicious activity involving the FMC web interface and user sessions.
Evidence notes
All claims above are taken from the supplied CVE/NVD fields and the cited official links. The corpus states: authenticated remote attacker, XSS against a user of the web interface, known affected release 6.2.1, CVSS v3.0 5.4 with vector AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N, and CWE-79. No fixed version or exploit details were provided in the supplied source data.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-3847 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-3847
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-3847 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3847
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-fpmc
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.