Cross-Site Scripting Issue in Cisco Firepower Management Interface
CVE-2015-6372

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
18 November 2015

Summary

The vulnerability in the web-based management interface of Cisco Firepower Extensible Operating System allows remote attackers to exploit insufficient validation of user-supplied input. By injecting arbitrary web script or HTML through a crafted value, attackers may execute malicious scripts in the context of a user's session. This could lead to unauthorized actions on behalf of users, potentially compromising sensitive information and network integrity.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.