Cross-origin Domain Vulnerability in Cisco Firepower Management Console
CVE-2018-0278

6.5MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
2 May 2018

Summary

A vulnerability in the management console of Cisco Firepower System Software enables unauthenticated remote attackers to gain access to sensitive system data. This issue arises from inadequate cross-origin domain protections associated with the WebSocket protocol. Attackers can exploit this by enticing users to visit a malicious site that can send unauthorized requests to the affected application while an active session is maintained. Successful exploitation could lead to the leakage of policy or configuration data, potentially allowing further attacks on the management console.

Affected Version(s)

Cisco Firepower System Software Cisco Firepower System Software

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.