Cross-origin Domain Vulnerability in Cisco Firepower Management Console
CVE-2018-0278
6.5MEDIUM
Summary
A vulnerability in the management console of Cisco Firepower System Software enables unauthenticated remote attackers to gain access to sensitive system data. This issue arises from inadequate cross-origin domain protections associated with the WebSocket protocol. Attackers can exploit this by enticing users to visit a malicious site that can send unauthorized requests to the affected application while an active session is maintained. Successful exploitation could lead to the leakage of policy or configuration data, potentially allowing further attacks on the management console.
Affected Version(s)
Cisco Firepower System Software Cisco Firepower System Software
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved