CVE-2015-4302
published 2015-08-19CVE-2015-4302: The web interface in Cisco FireSIGHT Management Center 5.3.1.4 allows remote attackers to delete arbitrary system policies via modified parameters in a POST…
PriorityP339medium6.4CVSS 2.0
AVNACLAuNCNIPAP
EPSS
2.15%
80.1th percentile
The web interface in Cisco FireSIGHT Management Center 5.3.1.4 allows remote attackers to delete arbitrary system policies via modified parameters in a POST request, aka Bug ID CSCuu25390.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firesight_system_software | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
vendor_cisco6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco FireSIGHT Management Center System Policy Deletion Vulnerability
vendor_cisco·2015-08-13·CVSS 6.4
CVE-2015-4302 [MEDIUM] CWE-20 Cisco FireSIGHT Management Center System Policy Deletion Vulnerability
Cisco FireSIGHT Management Center System Policy Deletion Vulnerability
A vulnerability in the web interface function to delete a system policy configured in the Cisco FireSIGHT Management Center application could allow unauthenticated, remote attackers to delete a system policy other than their own.
The vulnerability is due to improper input validation of certain fields of the HTTP POST request. An attacker could exploit this vulnerability by sending a crafted HTTP POST request with parameters of another system policy that the attacker is not authorized to delete. An exploit could allow the attacker to compromise the integrity of the application by the unexpected removal of a system policy. Availability may also be affected.
Cisco has confirmed the vulnerability; however, updates are un
GHSA
GHSA-r9jq-vwjm-mmc4: The web interface in Cisco FireSIGHT Management Center 5
ghsa_unreviewed·2022-05-17
CVE-2015-4302 [MEDIUM] CWE-284 GHSA-r9jq-vwjm-mmc4: The web interface in Cisco FireSIGHT Management Center 5
The web interface in Cisco FireSIGHT Management Center 5.3.1.4 allows remote attackers to delete arbitrary system policies via modified parameters in a POST request, aka Bug ID CSCuu25390.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-08-19
Published