FTP API Vulnerability in Cisco Firepower System Software
CVE-2016-6460

7.5HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
19 November 2016

Summary

A vulnerability exists in the FTP Representational State Transfer API within Cisco Firepower System Software, which could enable an unauthenticated remote attacker to bypass configured malware detection rules. This flaw is particularly concerning for systems employing file policies to block malware over FTP connections, allowing a potential attacker to download malicious software. Affected versions of Cisco Firepower include 5.4 and 6.x series, emphasizing the need for users to verify their systems are updated to avoid exploitation.

Affected Version(s)

Cisco Firepower System Software 5.4.0.2 through 6.2.0 Cisco Firepower System Software 5.4.0.2 through 6.2.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.