First published: Sat Jan 16 2016(Updated: )
Cross-site scripting (XSS) vulnerability in the Management Center in Cisco FireSIGHT System Software 6.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted cookie, aka Bug ID CSCuw89094.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco FireSIGHT System Software | =6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1294 is categorized as a medium severity vulnerability due to its potential to allow cross-site scripting attacks.
To address CVE-2016-1294, upgrade to a patched version of Cisco FireSIGHT System Software that resolves the XSS issue.
CVE-2016-1294 affects users of Cisco FireSIGHT System Software version 6.0.1.
Exploiting CVE-2016-1294 allows remote attackers to inject arbitrary web scripts or HTML, potentially leading to unauthorized actions on behalf of users.
There are no effective workarounds for CVE-2016-1294; the best course of action is to apply the recommended software update.