CVE-2009-2344: Critical severity cisco sourcefire defense center vulnerability
The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain privileges via a $admin value for the admin parameter in an edit action to admin/user/user.cgi and unspecified other components.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2344?
CVE-2009-2344 has been classified with a high severity due to the risk of remote authenticated users gaining privileged access.
How do I fix CVE-2009-2344?
To mitigate CVE-2009-2344, update Sourcefire Defense Center and 3D Sensor to version 4.8.2 or later.
Who is affected by CVE-2009-2344?
CVE-2009-2344 affects users of Sourcefire Defense Center versions up to 4.8.1 and 3D Sensor versions up to 4.8.1.
What type of vulnerability is CVE-2009-2344?
CVE-2009-2344 is a privilege escalation vulnerability that allows unauthorized access to admin features.
Can unauthenticated users exploit CVE-2009-2344?
No, only remote authenticated users can exploit CVE-2009-2344 to gain elevated privileges.