First published: Wed Oct 05 2016(Updated: )
SQL injection vulnerability in Cisco Firepower Management Center 4.10.3 through 5.4.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCur25485.
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure Firewall Management Center | =4.10.3 | |
Cisco Secure Firewall Management Center | =5.2.0 | |
Cisco Secure Firewall Management Center | =5.3.0 | |
Cisco Secure Firewall Management Center | =5.3.1 | |
Cisco Secure Firewall Management Center | =5.4.0 | |
Cisco Firepower Management Center Software | =4.10.3 | |
Cisco Firepower Management Center Software | =5.2.0 | |
Cisco Firepower Management Center Software | =5.3.0 | |
Cisco Firepower Management Center Software | =5.3.1 | |
Cisco Firepower Management Center Software | =5.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6419 has a medium severity rating, as it allows remote authenticated users to execute arbitrary SQL commands.
To fix CVE-2016-6419, upgrade to Cisco Firepower Management Center version 5.4.1 or later.
CVE-2016-6419 affects Cisco Firepower Management Center versions 4.10.3 through 5.4.0.
CVE-2016-6419 can be exploited by remote authenticated users with access to the vulnerable Cisco Firepower Management Center.
CVE-2016-6419 is categorized as an SQL injection vulnerability.