CVE-2015-6368: Infoleak
Published Nov 19, 2015
·Updated
Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, aka Bug ID CSCux10608.
Affected Software
1 affected component
Cisco Firepower Extensible Operating System=1.1\(1.160\)
Event History
Nov 19, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6368?
CVE-2015-6368 has a medium severity rating, as it allows remote attackers to read files on affected Cisco devices.
2
How do I fix CVE-2015-6368?
To mitigate CVE-2015-6368, upgrade to a version of Cisco Firepower Extensible Operating System that is not vulnerable, as detailed in Cisco's security advisories.
3
What devices are affected by CVE-2015-6368?
CVE-2015-6368 specifically affects Cisco Firepower 9000 devices running Firepower Extensible Operating System version 1.1(1.160).
4
Can CVE-2015-6368 be exploited remotely?
Yes, CVE-2015-6368 can be exploited remotely through crafted HTTP requests.
5
What does CVE-2015-6368 allow attackers to do?
CVE-2015-6368 allows remote attackers to read files on the affected Cisco Firepower devices.