Vulnslist

find the latest Cisco vulnerabilities

Cisco Firepower 9000 Series Switch Clickjacking Vulnerability

cisco-sa-20151117-firepower4 · Medium · Published · Updated

A vulnerability in the web interface of the Cisco Firepower 9000 Series Switch could allow an unauthenticated, remote attacker to affect the integrity of the device though a clickjacking or phishing attack. The vulnerability is due to the lack of proper input sanitization of iFrame data in the HTTP requests sent to the device. An attacker could exploit this vulnerability by sending crafted HTTP packets with malicious iFrame data. An exploit could allow the attacker to perform a clickjacking or phishing attack where the user is tricked into clicking a malicious link. Protection mechanisms should be used to help prevent this type of attack. Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151117-firepower4

Workarounds

Workarounds are not available.

CVEsCVE-2015-6374
Cisco Bug IDsCSCux10604
CVSS ScoreBase 5.0
Base 5.0 AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:C
Product Names From Source
Cisco Firepower Extensible Operating System, Firepower Extensible Operating System

Related Products

Product CVE Evidence
Firepower Extensible Operating System CVE-2015-6374 Cisco OpenVuln
Cisco Firepower Extensible Operating System CVE-2015-6374 Cisco OpenVuln
Cisco Firepower 9000 Series CVE-2015-6374 Cisco OpenVuln