8.8
CVSSv3

CVE-2016-1457

Published: 18/08/2016 Updated: 16/08/2017
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

The web-based GUI in Cisco Firepower Management Center 4.x and 5.x prior to 5.3.1.2 and 5.4.x prior to 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x prior to 5.3.1.2 and 5.4.x prior to 5.4.0.1 allows remote authenticated users to execute arbitrary commands as root via crafted HTTP requests, aka Bug ID CSCur25513.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco firepower management center 5.3.0.4

cisco firepower management center 5.2.0

cisco firepower management center 5.3.1

cisco firepower management center 5.4.0

cisco firepower management center 4.10.3.9

Vendor Advisories

A vulnerability in the web-based GUI of Cisco Firepower Management Center and Cisco Adaptive Security Appliance (ASA) 5500-X Series with FirePOWER Services could allow an authenticated, remote attacker to perform unauthorized remote command execution on the affected device The vulnerability is due to insufficient authorization checking An attack ...