First published: Wed Jul 08 2015(Updated: )
Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 5.4.1.2 and 6.0.0 in FireSIGHT Management Center allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu94721.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco FireSIGHT System Software | =5.4.1.2 | |
Cisco FireSIGHT System Software | =6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVEs severity is classified as high due to the potential for remote attackers to hijack user authentication.
To fix CVE-2015-4242, you should update Cisco FireSIGHT System Software to the latest patched version available.
CVE-2015-4242 affects Cisco FireSIGHT System Software versions 5.4.1.2 and 6.0.0.
Yes, CVE-2015-4242 can be exploited remotely by attackers without physical access to the system.
CVE-2015-4242 is categorized as a cross-site request forgery (CSRF) vulnerability.