FTP API Vulnerability in Cisco Firepower System Software
CVE-2016-6460
7.5HIGH
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 19 November 2016
What is CVE-2016-6460?
A vulnerability exists in the FTP Representational State Transfer API within Cisco Firepower System Software, which could enable an unauthenticated remote attacker to bypass configured malware detection rules. This flaw is particularly concerning for systems employing file policies to block malware over FTP connections, allowing a potential attacker to download malicious software. Affected versions of Cisco Firepower include 5.4 and 6.x series, emphasizing the need for users to verify their systems are updated to avoid exploitation.
Affected Version(s)
Cisco Firepower System Software 5.4.0.2 through 6.2.0 Cisco Firepower System Software 5.4.0.2 through 6.2.0