CVE-2015-6357: Input Validation
The rule-update feature in Cisco FireSIGHT Management Center (MC) 5.2 through 5.4.0.1 does not verify the X.509 certificate of the support.sourcefire.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide an invalid package, and consequently execute arbitrary code, via a crafted certificate, aka Bug ID CSCuw06444.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6357?
CVE-2015-6357 has a high severity rating due to its potential to allow arbitrary code execution via man-in-the-middle attacks.
How do I fix CVE-2015-6357?
To fix CVE-2015-6357, users should update their Cisco FireSIGHT Management Center to a patched version provided by Cisco.
Which versions of Cisco FireSIGHT are affected by CVE-2015-6357?
CVE-2015-6357 affects Cisco FireSIGHT Management Center versions 5.2.0 through 5.4.0.1.
What type of attack does CVE-2015-6357 facilitate?
CVE-2015-6357 can facilitate man-in-the-middle attacks that allow an attacker to spoof a valid server.
What are the potential consequences of CVE-2015-6357?
The potential consequences of CVE-2015-6357 include execution of arbitrary code and manipulation of software updates.