CVE-2016-1394: High severity cisco firesight system vulnerability
Published Jul 3, 2016
·Updated
Cisco Firepower System Software 6.0.0 through 6.1.0 has a hardcoded account, which allows remote attackers to obtain CLI access by leveraging knowledge of the password, aka Bug ID CSCuz56238.
Affected Software
4 affected components
cisco FireSIGHT System software=6.0.0
cisco FireSIGHT System software=6.0.0.1
cisco FireSIGHT System software=6.0.1
cisco FireSIGHT System software=6.1.0
Event History
Jul 3, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1394?
CVE-2016-1394 is considered to have a high severity due to the potential for remote unauthorized access.
2
How do I fix CVE-2016-1394?
To fix CVE-2016-1394, update Cisco Firepower System Software to a version later than 6.1.0.
3
What versions are affected by CVE-2016-1394?
CVE-2016-1394 affects Cisco Firepower System Software versions 6.0.0 to 6.1.0.
4
What type of vulnerability is CVE-2016-1394?
CVE-2016-1394 is a hardcoded credential vulnerability that allows CLI access to unauthorized users.
5
Who can exploit CVE-2016-1394?
Remote attackers who are aware of the hardcoded password can exploit CVE-2016-1394.