4
CVSSv2

CVE-2016-6435

Published: 06/10/2016 Updated: 03/09/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

A vulnerability in the web console of Cisco Firepower Management Center could allow an authenticated, remote malicious user to access sensitive information. The vulnerability is due to improper validation of parameters that are sent to the web console of an affected system. The vulnerability could allow an authenticated console user to access files that are readable by the www user on the server. An attacker who has user privileges for the web console could leverage this vulnerability to read some of the files on the underlying operating system. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-ftmc2

Vulnerable Product Search on Vulmon Subscribe to Product

cisco firepower management center 6.0.1

Vendor Advisories

A vulnerability in the web console of Cisco Firepower Management Center could allow an authenticated, remote attacker to access sensitive information The vulnerability is due to improper validation of parameters that are sent to the web console of an affected system The vulnerability could allow an authenticated console user to access files that ...

Exploits

KL-001-2016-006 : Cisco Firepower Threat Management Console Local File Inclusion Title: Cisco Firepower Threat Management Console Local File Inclusion Advisory ID: KL-001-2016-006 Publication Date: 20161005 Publication URL: wwwkorelogiccom/Resources/Advisories/KL-001-2016-006txt 1 Vulnerability Details Affected Vendor: Cisco ...