5.8
CVSSv2

CVE-2016-6394

Published: 12/09/2016 Updated: 28/11/2016
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software up to and including 6.1.0 allows remote malicious users to hijack web sessions via a session identifier, aka Bug ID CSCuz80503.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco firesight system software 5.2.0.3

cisco firesight system software 5.2.0.4

cisco firesight system software 5.3.1.1

cisco firesight system software 6.0.0

cisco firesight system software 5.3.1.4

cisco firesight system software 5.4.0.1

cisco firesight system software 5.3.0.3

cisco firesight system software 5.3.0.4

cisco firesight system software 5.4.0.6

cisco firesight system software 5.2.0

cisco firesight system software 5.3.0

cisco firesight system software 5.3.0.1

cisco firesight system software 5.3.0.2

cisco firesight system software 5.3.1

cisco firesight system software 5.4.1.2

cisco firesight system software 5.4.1.3

cisco firesight system software 5.4.1.4

cisco firesight system software 6.0.0.1

cisco firesight system software 5.3.0.7

cisco firesight system software 5.4.0.2

cisco firesight system software 5.2.0.1

cisco firesight system software 5.2.0.2

cisco firesight system software 5.4.0

cisco firesight system software 5.4.1

cisco firesight system software 5.3.1.5

cisco firesight system software 5.2.0.8

cisco firesight system software 6.0.1

cisco firesight system software 6.1.0

cisco firesight system software 5.4.0.3

cisco firesight system software 5.4.0.5

cisco firesight system software 5.2.0.5

cisco firesight system software 5.2.0.6

cisco firesight system software 5.3.1.2

cisco firesight system software 5.3.1.3

cisco firesight system software 5.3.1.7

cisco firesight system software 5.4.0.4

cisco firesight system software 5.3.0.5

cisco firesight system software 5.3.0.6

Vendor Advisories

A vulnerability in session identification management functionality of the web-based management interface for Cisco Firepower Management Center and Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to hijack a valid user session The vulnerability exists because the affected application does not assign a new session id ...