5
CVSSv2

CVE-2016-1342

Published: 26/02/2016 Updated: 04/03/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The device login page in Cisco FirePOWER Management Center 5.3 up to and including 6.0.0.1 allows remote malicious users to obtain potentially sensitive software-version information by reading help files, aka Bug ID CSCuy36654.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco firepower management center 5.4.1.4

cisco firepower management center 5.4.1.1

cisco firepower management center 6.0.0.1

cisco firepower management center 5.3.1.3

cisco firepower management center 5.4_base

cisco firepower management center 5.4.1.3

cisco firepower management center 5.3.1.5

cisco firepower management center 5.3.1.6

cisco firepower management center 5.3_base

cisco firepower management center 5.4.1

cisco firepower management center 5.4.0

cisco firepower management center 6.0_base

cisco firepower management center 6.0.0

cisco firepower management center 5.4.1.5

cisco firepower management center 5.4.1.2

cisco firepower management center 5.3.0.3

cisco firepower management center 5.3.1.4

Vendor Advisories

A vulnerability in the Cisco FirePOWER Management Center could allow an unauthenticated, remote attacker to obtain information about the Cisco FirePOWER Management Center software version from the device login page The vulnerability is due to verbose output returned when HTML files are retrieved from the affected system An attacker could exploit ...