CVE-2015-6354: XSS
Published Oct 31, 2015
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight Management Center (MC) 5.4.1.3 and 6.0 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuv73338.
Affected Software
2 affected components
cisco FireSIGHT System software=5.4.1.3
cisco FireSIGHT System software=6.0.0
Event History
Oct 31, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6354?
CVE-2015-6354 has a high severity due to the potential for remote code execution through cross-site scripting.
2
How do I fix CVE-2015-6354?
To fix CVE-2015-6354, upgrade Cisco FireSight Management Center to version 6.0.1 or later as recommended by Cisco.
3
What systems are affected by CVE-2015-6354?
CVE-2015-6354 affects Cisco FireSight Management Center versions 5.4.1.3 and 6.0.0.
4
Who can exploit CVE-2015-6354?
Remote authenticated users can exploit CVE-2015-6354 due to the vulnerabilities present in the system.
5
What type of vulnerability is CVE-2015-6354?
CVE-2015-6354 is classified as a cross-site scripting (XSS) vulnerability.