Vulnslist

find the latest Cisco vulnerabilities

Cisco Firepower 9000 Unauthenticated File Access Vulnerability

cisco-sa-20151116-firepower · Medium · Published · Updated

A vulnerability in the web interface of the Cisco Firepower 9000 Series Switches could allow an unauthenticated, remote attacker to view certain files on the device that should be restricted.   The vulnerability is due to lack of proper authentication checks when a request to download and view a file is received. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151116-firepower

Workarounds

Workarounds are not available.

CVEsCVE-2015-6368
Cisco Bug IDsCSCux10608
CVSS ScoreBase 5.0
Base 5.0 AV:N/AC:L/Au:N/C:P/I:N/A:N/E:F/RL:U/RC:C
Product Names From Source
Cisco Firepower Extensible Operating System, Firepower Extensible Operating System

Related Products

Product CVE Evidence
Firepower Extensible Operating System CVE-2015-6368 Cisco OpenVuln
Cisco Firepower Extensible Operating System CVE-2015-6368 Cisco OpenVuln
Cisco Firepower 9000 Series CVE-2015-6368 Cisco OpenVuln