First published: Wed Oct 05 2016(Updated: )
Cisco FireSIGHT System Software 4.10.3 through 5.4.0 in Firepower Management Center allows remote authenticated users to bypass authorization checks and gain privileges via a crafted HTTP request, aka Bug ID CSCur25467.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco FireSIGHT System Software | =4.10.3 | |
Cisco FireSIGHT System Software | =5.2.0 | |
Cisco FireSIGHT System Software | =5.3.0 | |
Cisco FireSIGHT System Software | =5.3.1 | |
Cisco FireSIGHT System Software | =5.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6420 is considered a high severity vulnerability due to its potential to allow unauthorized privilege escalation.
To fix CVE-2016-6420, upgrade your Cisco FireSIGHT System Software to a patched version beyond 5.4.0.
Remote authenticated users of Cisco FireSIGHT System Software versions 4.10.3 through 5.4.0 are affected by CVE-2016-6420.
CVE-2016-6420 can lead to unauthorized access and privilege escalation for attackers with valid credentials.
There are no known workarounds for CVE-2016-6420; upgrading to a secure version is recommended.