CVE-2015-6380: OS Command Injection
An unspecified script in the web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to execute arbitrary OS commands via crafted parameters, aka Bug ID CSCux10622.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6380?
CVE-2015-6380 is classified as a high-severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2015-6380?
To mitigate CVE-2015-6380, update the Cisco Firepower Extensible Operating System to a version that addresses the vulnerability.
Who is affected by CVE-2015-6380?
CVE-2015-6380 affects Cisco Firepower 9000 devices running Firepower Extensible Operating System version 1.1(1.160).
What type of attack is associated with CVE-2015-6380?
CVE-2015-6380 allows remote authenticated users to execute arbitrary operating system commands on the affected devices.
Is CVE-2015-6380 being actively exploited?
As of the last update, there have been no public reports of active exploitation of CVE-2015-6380, but it remains a concerning vulnerability.