HTTP Attack Detection Bypass in Cisco FireSIGHT Management Center
CVE-2015-6427

Currently unrated

Key Information:

Vendor

Cisco

Vendor
CVE Published:
18 December 2015

What is CVE-2015-6427?

The vulnerability in Cisco FireSIGHT Management Center allows remote attackers to bypass the HTTP attack detection mechanism. This is achieved through an SSL session mishandled post-decryption, enabling attackers to evade Snort intrusion detection system rules. This security flaw poses a significant risk as it undermines the ability of the system to properly detect and respond to malicious HTTP traffic.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.