5
CVSSv2

CVE-2015-6427

Published: 18/12/2015 Updated: 07/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cisco FireSIGHT Management Center allows remote malicious users to bypass the HTTP attack detection feature and avoid triggering Snort IDS rules via an SSL session that is mishandled after decryption, aka Bug ID CSCux53437.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco firesight system software 5.4.0.1

cisco firesight system software 5.3.1.4

cisco firesight system software 5.3.1.1

cisco firesight system software 5.4.1

cisco firesight system software 6.0.1

cisco firesight system software 6.0.0.1

cisco firesight system software 5.3.1.5

cisco firesight system software 5.4.1.2

cisco firesight system software 5.4.0

cisco firesight system software 5.3.0.2

cisco firesight system software 5.4.0.4

cisco firesight system software 5.3.1.7

cisco firesight system software 5.3.1.2

cisco firesight system software 6.0.0

cisco firesight system software 5.4.1.4

cisco firesight system software 5.4.1.3

cisco firesight system software 5.3.1

cisco firesight system software 5.3.1.3

cisco firesight system software 5.3.0.1

cisco firesight system software 5.3.0

Vendor Advisories

A vulnerability in HTTP attack detection within decrypted SSL traffic of Cisco FireSIGHT Management Center could allow an unauthenticated, remote attacker to bypass HTTP attack detection The traffic is SSL and the application is configured to decrypt the SSL connection and detect HTTP-based attacks that are associated with Snort intrusion detectio ...