First published: Fri Jun 12 2015(Updated: )
Cisco FireSIGHT System Software 5.3.1.3 and 6.0.0 allows remote authenticated users to delete an arbitrary user's dashboard via a modified VPN deletion request in a management session, aka Bug ID CSCut67078.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco FireSIGHT System Software | =5.3.1.1 | |
Cisco FireSIGHT System Software | =6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0773 has been rated as a medium severity vulnerability due to its potential impact on user data integrity.
To fix CVE-2015-0773, upgrade to Cisco FireSIGHT System Software version 5.3.1.4 or later, or 6.0.1 or later.
CVE-2015-0773 affects remote authenticated users of Cisco FireSIGHT System Software 5.3.1.3 and 6.0.0.
Attackers leveraging CVE-2015-0773 can delete an arbitrary user's dashboard through a modified VPN deletion request.
CVE-2015-0773 was disclosed in early 2015.