CVE-2015-0773
published 2015-06-12CVE-2015-0773: Cisco FireSIGHT System Software 5.3.1.3 and 6.0.0 allows remote authenticated users to delete an arbitrary user's dashboard via a modified VPN deletion request…
PriorityP429medium5.5CVSS 2.0
AVNACLAuSCNIPAP
EPSS
1.60%
73.1th percentile
Cisco FireSIGHT System Software 5.3.1.3 and 6.0.0 allows remote authenticated users to delete an arbitrary user's dashboard via a modified VPN deletion request in a management session, aka Bug ID CSCut67078.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
CVSS provenance
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
vendor_cisco5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco FireSIGHT Management Center Dashboard Deletion Vulnerability
vendor_cisco·2015-06-09·CVSS 5.5
CVE-2015-0773 [MEDIUM] CWE-399 Cisco FireSIGHT Management Center Dashboard Deletion Vulnerability
Cisco FireSIGHT Management Center Dashboard Deletion Vulnerability
A vulnerability in management interface used to delete VPNs in the Cisco FireSIGHT Management Center could allow an authenticated, remote attacker with limited user permissions to delete another user's VPN dashboard.
The vulnerability occurs because the product does not properly validate the deletion request. An attacker could exploit this vulnerability by tampering with a management session and modifying the deletion request. An exploit could allow the attacker to delete dashboards that the user account should not be able to modify.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement decreases
GHSA
GHSA-xf6v-7wcc-qvvf: Cisco FireSIGHT System Software 5
ghsa_unreviewed·2022-05-17
CVE-2015-0773 [MEDIUM] GHSA-xf6v-7wcc-qvvf: Cisco FireSIGHT System Software 5
Cisco FireSIGHT System Software 5.3.1.3 and 6.0.0 allows remote authenticated users to delete an arbitrary user's dashboard via a modified VPN deletion request in a management session, aka Bug ID CSCut67078.
No detection rules found.
No public exploits indexed.
2015-06-12
Published