CVE-2015-4287
published 2015-07-29CVE-2015-4287: Cisco Firepower Extensible Operating System 1.1(1.86) on Firepower 9000 devices allows remote attackers to bypass intended access restrictions and obtain…
PriorityP424medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.27%
66.5th percentile
Cisco Firepower Extensible Operating System 1.1(1.86) on Firepower 9000 devices allows remote attackers to bypass intended access restrictions and obtain sensitive device information by visiting an unspecified web page, aka Bug ID CSCuu82230.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firepower_extensible_operating_system | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h2x7-9hr9-34xw: Cisco Firepower Extensible Operating System 1
ghsa_unreviewed·2022-05-17
CVE-2015-4287 [MEDIUM] GHSA-h2x7-9hr9-34xw: Cisco Firepower Extensible Operating System 1
Cisco Firepower Extensible Operating System 1.1(1.86) on Firepower 9000 devices allows remote attackers to bypass intended access restrictions and obtain sensitive device information by visiting an unspecified web page, aka Bug ID CSCuu82230.
Cisco
Cisco Firepower 9000 Series Unauthenticated Web Page Vulnerability
vendor_cisco·2015-07-27·CVSS 5.0
CVE-2015-4287 [MEDIUM] CWE-264 Cisco Firepower 9000 Series Unauthenticated Web Page Vulnerability
Cisco Firepower 9000 Series Unauthenticated Web Page Vulnerability
A vulnerability in the web interface of the Cisco Firepower 9000 device could allow an unauthenticated, remote attacker to access a web page that should be restricted.
The vulnerability is due to improper authentication validation. An attacker could exploit this vulnerability by accessing a certain web page on the Cisco Firepower 9000 device that should be restricted to authenticated users. An exploit could allow the attacker to access details about the Cisco Firepower 9000 device that should be available only to an authenticated user.
Cisco has confirmed the vulnerability; however, software updates are not available.
To exploit this vulnerability, an attacker may need access to trusted, internal networks to access a c
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-07-29
Published