First published: Thu Nov 19 2015(Updated: )
Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, aka Bug ID CSCux10608.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Firepower Extensible Operating System | =1.1\(1.160\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6368 has a medium severity rating, as it allows remote attackers to read files on affected Cisco devices.
To mitigate CVE-2015-6368, upgrade to a version of Cisco Firepower Extensible Operating System that is not vulnerable, as detailed in Cisco's security advisories.
CVE-2015-6368 specifically affects Cisco Firepower 9000 devices running Firepower Extensible Operating System version 1.1(1.160).
Yes, CVE-2015-6368 can be exploited remotely through crafted HTTP requests.
CVE-2015-6368 allows remote attackers to read files on the affected Cisco Firepower devices.