CVE-2015-6368
published 2015-11-19CVE-2015-6368: Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, aka Bug ID…
PriorityP431medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.22%
65.2th percentile
Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, aka Bug ID CSCux10608.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firepower_9000_unauthenticated_file_access | — | — |
| cisco | firepower_extensible_operating_system | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Firepower 9000 Unauthenticated File Access Vulnerability
vendor_cisco·2015-11-16·CVSS 5.0
CVE-2015-6368 [MEDIUM] CWE-264 Cisco Firepower 9000 Unauthenticated File Access Vulnerability
Cisco Firepower 9000 Unauthenticated File Access Vulnerability
A vulnerability in the web interface of the Cisco Firepower 9000 Series Switches could allow an unauthenticated, remote attacker to view certain files on the device that should be restricted.
The vulnerability is due to lack of proper authentication checks when a request to download and view a file is received. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device.
Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151116-firepower
Cisco
Cisco Firepower 9000 Unauthenticated File Access Vulnerability
vendor_cisco
CVE-2015-6368 Cisco Firepower 9000 Unauthenticated File Access Vulnerability
CVE-2015-6368: Cisco Firepower 9000 Unauthenticated File Access Vulnerability
A vulnerability in the web interface of the Cisco Firepower 9000 Series Switches could allow an unauthenticated, remote attacker to view certain files on the device that should be restricted. The vulnerability is due to lack of proper authentication checks when a request to download and view a file is received. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. Cisco has not released software updates that address this vulnerability.
CWE: CWE-264, CWE-264
Bug IDs: CSCux10608
GHSA
GHSA-gm6g-v46p-p26m: Cisco Firepower Extensible Operating System 1
ghsa_unreviewed·2022-05-17
CVE-2015-6368 [MEDIUM] CWE-200 GHSA-gm6g-v46p-p26m: Cisco Firepower Extensible Operating System 1
Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, aka Bug ID CSCux10608.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-11-19
Published