First published: Sun Jul 03 2016(Updated: )
Cisco Firepower System Software 6.0.0 through 6.1.0 has a hardcoded account, which allows remote attackers to obtain CLI access by leveraging knowledge of the password, aka Bug ID CSCuz56238.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco FireSIGHT System Software | =6.0.0 | |
Cisco FireSIGHT System Software | =6.0.0.1 | |
Cisco FireSIGHT System Software | =6.0.1 | |
Cisco FireSIGHT System Software | =6.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1394 is considered to have a high severity due to the potential for remote unauthorized access.
To fix CVE-2016-1394, update Cisco Firepower System Software to a version later than 6.1.0.
CVE-2016-1394 affects Cisco Firepower System Software versions 6.0.0 to 6.1.0.
CVE-2016-1394 is a hardcoded credential vulnerability that allows CLI access to unauthorized users.
Remote attackers who are aware of the hardcoded password can exploit CVE-2016-1394.