First published: Thu Oct 06 2016(Updated: )
The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug ID CSCva30376.
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure Firewall Management Center | =6.0.1 | |
Cisco Firepower Management Center Software | =6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6435 has a medium severity rating, allowing unauthorized file access by authenticated users.
To fix CVE-2016-6435, upgrade your Cisco Firepower Management Center to a patched version that addresses this vulnerability.
CVE-2016-6435 affects users of Cisco Secure Firewall Management Center and Cisco Firepower Management Center running version 6.0.1.
CVE-2016-6435 facilitates unauthorized access to arbitrary files on the system through crafted parameters.
Yes, successful exploitation of CVE-2016-6435 requires that the attacker has remote authenticated access to the web console.