Cross-Site Scripting Vulnerability in Cisco FireSIGHT Management Center
CVE-2016-1294
6.1MEDIUM
Summary
A cross-site scripting (XSS) vulnerability exists in the Management Center of Cisco FireSIGHT System Software version 6.0.1. This flaw permits remote attackers to inject arbitrary web scripts or HTML content through specially crafted cookies. Successful exploitation of this vulnerability could allow attackers to execute malicious scripts in the context of authenticated users, potentially leading to data theft or unauthorized access. It is crucial for organizations using affected versions to apply security updates and implement robust security measures to mitigate potential risks.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved