First published: Sat Oct 31 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight Management Center (MC) 5.3.1.5 and 5.4.x through 5.4.1.3 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuu28922.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco FireSIGHT System Software | =5.3.1.5 | |
Cisco FireSIGHT System Software | =5.4.0 | |
Cisco FireSIGHT System Software | =5.4.0.1 | |
Cisco FireSIGHT System Software | =5.4.0.4 | |
Cisco FireSIGHT System Software | =5.4.1 | |
Cisco FireSIGHT System Software | =5.4.1.2 | |
Cisco FireSIGHT System Software | =5.4.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6353 is classified as a high severity vulnerability due to the potential for remote authenticated users to perform cross-site scripting attacks.
To fix CVE-2015-6353, upgrade to the latest version of Cisco FireSight Management Center that addresses this vulnerability.
CVE-2015-6353 affects Cisco FireSight Management Center versions 5.3.1.5 and 5.4.x through 5.4.1.3.
CVE-2015-6353 allows remote authenticated users to inject arbitrary web scripts or HTML, enabling potential cross-site scripting attacks.
CVE-2015-6353 can be exploited by remote authenticated users who have access to the Cisco FireSight Management Center.