CVE-2015-6419: Infoleak
Published Dec 12, 2015
·Updated
Cisco FireSIGHT Management Center with software 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote authenticated users to read arbitrary files via a crafted GET request, aka Bug ID CSCur25410.
Affected Software
5 affected components
cisco FireSIGHT System software=4.10.3
cisco FireSIGHT System software=5.2.0
cisco FireSIGHT System software=5.3.0
cisco FireSIGHT System software=5.3.1
cisco FireSIGHT System software=5.4.0
Event History
Dec 12, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6419?
CVE-2015-6419 is classified as a high severity vulnerability due to its ability to allow remote authenticated users to read arbitrary files.
2
How do I fix CVE-2015-6419?
To mitigate CVE-2015-6419, upgrade your Cisco FireSIGHT Management Center to a version that addresses this vulnerability.
3
What software versions are affected by CVE-2015-6419?
CVE-2015-6419 affects Cisco FireSIGHT Management Center with software versions 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0.
4
Can CVE-2015-6419 be exploited remotely?
Yes, CVE-2015-6419 can be exploited by remote authenticated users via a crafted GET request.
5
What type of access does CVE-2015-6419 allow?
CVE-2015-6419 allows affected users to read arbitrary files on the system.