CVE-2015-4302: Medium severity cisco firesight system vulnerability
Published Aug 19, 2015
·Updated
The web interface in Cisco FireSIGHT Management Center 5.3.1.4 allows remote attackers to delete arbitrary system policies via modified parameters in a POST request, aka Bug ID CSCuu25390.
Affected Software
1 affected component
cisco FireSIGHT System software=5.3.1.4
Event History
Aug 19, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4302?
CVE-2015-4302 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-4302?
To fix CVE-2015-4302, upgrade to Cisco FireSIGHT Management Center version 5.3.1.5 or later.
3
What types of attacks are possible with CVE-2015-4302?
CVE-2015-4302 allows remote attackers to delete arbitrary system policies by exploiting the web interface.
4
Which software versions are affected by CVE-2015-4302?
CVE-2015-4302 affects the Cisco FireSIGHT Management Center version 5.3.1.4.
5
Is CVE-2015-4302 related to remote access vulnerabilities?
Yes, CVE-2015-4302 is related to remote access vulnerabilities due to its exploitation through the web interface.