First published: Tue Aug 23 2016(Updated: )
Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.0.2, 5.3.1, and 5.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCur25508 and CSCur25518.
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure Firewall Management Center | =4.10.3 | |
Cisco Secure Firewall Management Center | =5.2.0 | |
Cisco Secure Firewall Management Center | =5.3.0 | |
Cisco Secure Firewall Management Center | =5.3.0.2 | |
Cisco Secure Firewall Management Center | =5.3.1 | |
Cisco Secure Firewall Management Center | =5.4.0 | |
Cisco Firepower Management Center Software | =4.10.3 | |
Cisco Firepower Management Center Software | =5.2.0 | |
Cisco Firepower Management Center Software | =5.3.0 | |
Cisco Firepower Management Center Software | =5.3.0.2 | |
Cisco Firepower Management Center Software | =5.3.1 | |
Cisco Firepower Management Center Software | =5.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6365 is classified as a high-severity cross-site scripting (XSS) vulnerability.
To fix CVE-2016-6365, update the Cisco Firepower Management Center to a version that is not vulnerable.
CVE-2016-6365 affects Cisco Firepower Management Center versions 4.10.3, 5.2.0, 5.3.0, 5.3.0.2, 5.3.1, and 5.4.0.
Yes, CVE-2016-6365 allows remote attackers to inject arbitrary web scripts or HTML.
The impacts of CVE-2016-6365 can include data theft, session hijacking, and other malicious actions through XSS.