PT-2016-6894 · Cisco · Firesight System
Published
2016-10-05
·
Updated
2017-07-30
·
CVE-2016-6420
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco FireSIGHT System Software versions 4.10.3 through 5.4.0
Description
The issue allows remote authenticated users to bypass authorization checks and gain privileges via a crafted HTTP request.
Recommendations
For versions 4.10.3 through 5.4.0, consider restricting access to the system until a patch is available to prevent unauthorized privilege escalation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Firesight System