Clickjacking Vulnerability in Cisco Firepower OS on Firepower 9000 Devices
CVE-2015-6374
Currently unrated
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 19 November 2015
What is CVE-2015-6374?
The web interface of Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices lacks proper restrictions for IFRAME elements. This oversight makes it susceptible to clickjacking attacks, enabling remote attackers to manipulate user interactions through deceitful web interfaces. Consequently, this vulnerability could facilitate other unspecified attacks when users are misled into clicking on malicious content, thereby compromising their security.