PT-2016-4770 · Cisco · Cisco Firepower Management Center

Published

2016-05-28

·

Updated

2024-11-26

·

CVE-2016-1413

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco Firepower Management Center versions 5.4.0 through 6.0.0.1
Description The issue allows remote authenticated users to modify pages by placing crafted code in a parameter value.
Recommendations For versions 5.4.0 through 6.0.0.1, consider restricting access to the web interface until a fix is available. Avoid using crafted code in parameter values to minimize the risk of exploitation.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2016-1413

Affected Products

Cisco Firepower Management Center