CVE-2015-4242

Severity
6.8MEDIUM
EPSS
0.1%
top 71.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 8
Latest updateMay 17

Description

Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 5.4.1.2 and 6.0.0 in FireSIGHT Management Center allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu94721.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages1 packages

NVDcisco/firesight_system_software5.4.1.2, 6.0.0+1

🔴Vulnerability Details

2
GHSA
GHSA-hp57-8q89-468c: Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 52022-05-17
CVEList
CVE-2015-4242: Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 52015-07-08

📋Vendor Advisories

1
Cisco
Cisco FireSIGHT Management Center Cross-Site Request Forgery Vulnerability2015-07-07
CVE-2015-4242 (MEDIUM CVSS 6.8) | Cross-site request forgery (CSRF) v | cvebase.io