Cross-Site Scripting Vulnerability in Cisco Firepower Management Center and FireSIGHT System Software
CVE-2016-6395

5.4MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
12 September 2016

Summary

A Cross-Site Scripting (XSS) vulnerability exists in the web-based management interface of Cisco Firepower Management Center and FireSIGHT System Software versions prior to 6.1. This flaw enables remote authenticated users to inject arbitrary web scripts or HTML through a specially crafted URL, potentially compromising the integrity and security of affected systems. Proper management and mitigation strategies are essential to safeguard against this type of exploit.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.