PT-2016-4770 · Cisco · Cisco Firepower Management Center
Published
2016-05-28
·
Updated
2024-11-26
·
CVE-2016-1413
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Firepower Management Center versions 5.4.0 through 6.0.0.1
Description
The issue allows remote authenticated users to modify pages by placing crafted code in a parameter value.
Recommendations
For versions 5.4.0 through 6.0.0.1, consider restricting access to the web interface until a fix is available. Avoid using crafted code in parameter values to minimize the risk of exploitation.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Firepower Management Center