9
CVSSv2

CVE-2016-1458

Published: 18/08/2016 Updated: 28/11/2016
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

The web-based GUI in Cisco Firepower Management Center 4.x and 5.x prior to 5.3.0.3, 5.3.1.x prior to 5.3.1.2, and 5.4.x prior to 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x prior to 5.3.0.3, 5.3.1.x prior to 5.3.1.2, and 5.4.x prior to 5.4.0.1 allows remote authenticated users to increase user-account privileges via crafted HTTP requests, aka Bug ID CSCur25483.

Affected Products

Vendor Product Versions
CiscoFirepower Management Center4.10.3, 5.2.0, 5.3.0, 5.3.1, 5.4.0

Vendor Advisories

A vulnerability in the web-based GUI of Cisco Firepower Management Center and Cisco Adaptive Security Appliance (ASA) 5500-X Series with FirePOWER Services could allow an authenticated, remote attacker to elevate the privileges of user accounts on the affected device The vulnerability is due to insufficient input validation An attacker could exp ...