PT-2016-6922 · Cisco · Cisco Fireamp Connector Endpoint
Publicado
2016-12-14
·
Atualizado
2016-12-15
·
CVE-2016-6449
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco FireAMP Connector Endpoint software version 1
Description
A vulnerability in the system management of certain FireAMP system processes could allow an authenticated, local attacker to stop certain protected FireAMP processes without requiring a password. This could cause a denial of service (DoS) condition, and certain security features could no longer be available.
Recommendations
For Cisco FireAMP Connector Endpoint software version 1, consider restricting access to the system management interface to prevent unauthorized process termination until a fix is available. As a temporary workaround, monitor system processes closely to quickly identify and respond to any potential denial of service conditions.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Fireamp Connector Endpoint