CVE-2015-6354
published 2015-10-31CVE-2015-6354: Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight Management Center (MC) 5.4.1.3 and 6.0 allow remote authenticated users to inject…
PriorityP412low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
1.08%
61.5th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight Management Center (MC) 5.4.1.3 and 6.0 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuv73338.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firesight_management_center_html | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco FireSIGHT Management Center HTML Injection Vulnerability
vendor_cisco·2015-10-29·CVSS 4.0
CVE-2015-6354 [MEDIUM] CWE-20 Cisco FireSIGHT Management Center HTML Injection Vulnerability
Cisco FireSIGHT Management Center HTML Injection Vulnerability
A vulnerability in the web interface of Cisco FireSIGHT Management Center (MC) could allow an authenticated, remote attacker to modify a page of the web interface.
The vulnerability is due to improper sanitization of parameter values. An attacker could exploit this vulnerability by injecting malicious code into an affected parameter and convincing the user to access a web page that would trigger the rendering of the injected code.
Cisco has not released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151029-fsmc2
Cisco
Cisco FireSIGHT Management Center HTML Injection Vulnerability
vendor_cisco
CVE-2015-6354 Cisco FireSIGHT Management Center HTML Injection Vulnerability
CVE-2015-6354: Cisco FireSIGHT Management Center HTML Injection Vulnerability
A vulnerability in the web interface of Cisco FireSIGHT Management Center (MC) could allow an authenticated, remote attacker to modify a page of the web interface. The vulnerability is due to improper sanitization of parameter values. An attacker could exploit this vulnerability by injecting malicious code into an affected parameter and convincing the user to access a web page that would trigger the rendering of the injected code. Cisco has not released software updates that address this vulnerability. There are no
CWE: CWE-20, CWE-20
Bug IDs: CSCuv73338
GHSA
GHSA-f525-2v5w-3f55: Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight Management Center (MC) 5
ghsa_unreviewed·2022-05-17
CVE-2015-6354 [LOW] CWE-79 GHSA-f525-2v5w-3f55: Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight Management Center (MC) 5
Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight Management Center (MC) 5.4.1.3 and 6.0 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuv73338.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-10-31
Published