PT-2016-6909 · Cisco · Cisco Firepower Management Center
Matt Bergin
+1
·
Published
2016-10-06
·
Updated
2024-11-26
·
CVE-2016-6435
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Firepower Management Center version 6.0.1
Description
The issue allows remote authenticated users to read arbitrary files via crafted parameters.
Recommendations
For Cisco Firepower Management Center version 6.0.1, consider restricting access to the web console until a patch is available. Avoid using crafted parameters in the web console to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Firepower Management Center