4.3
CVSSv2

CVE-2015-6374

Published: 19/11/2015 Updated: 19/11/2015
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices does not properly restrict use of IFRAME elements, which makes it easier for remote malicious users to conduct clickjacking attacks and unspecified other attacks via a crafted web site, aka Bug ID CSCux10604.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco firepower extensible operating system 1.1\\(1.160\\)

Vendor Advisories

A vulnerability in the web interface of the Cisco Firepower 9000 Series Switch could allow an unauthenticated, remote attacker to affect the integrity of the device though a clickjacking or phishing attack The vulnerability is due to the lack of proper input sanitization of iFrame data in the HTTP requests sent to the device An attacker could ex ...