CVE-2016-1345: Input Validation
Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote attackers to bypass malware protection via crafted fields in HTTP headers, aka Bug ID CSCux22726.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1345?
CVE-2016-1345 is rated as a high severity vulnerability due to its potential to allow remote attackers to bypass malware protection.
How do I fix CVE-2016-1345?
To fix CVE-2016-1345, update Cisco FireSIGHT System Software to version 6.0.1 or later and ASA with FirePOWER Services to version 6.0.0.1 or later.
Which Cisco products are affected by CVE-2016-1345?
CVE-2016-1345 affects Cisco FireSIGHT System Software versions 5.4.0 to 6.0.1 and ASA with FirePOWER Services versions 5.4.0 to 6.0.0.1.
What does CVE-2016-1345 exploit?
CVE-2016-1345 exploits crafted fields in HTTP headers to bypass malware protection mechanisms.
Is CVE-2016-1345 being actively exploited?
As of the last report, there have been no indications that CVE-2016-1345 is being actively exploited in the wild.