CVE-2015-6374
published 2015-11-19CVE-2015-6374: The web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices does not properly restrict use of IFRAME elements, which…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.84%
53.7th percentile
The web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, aka Bug ID CSCux10604.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firepower_9000_series_switch | — | — |
| cisco | firepower_extensible_operating_system | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wp3c-m2g9-hww6: The web interface in Cisco Firepower Extensible Operating System 1
ghsa_unreviewed·2022-05-17
CVE-2015-6374 [MEDIUM] CWE-20 GHSA-wp3c-m2g9-hww6: The web interface in Cisco Firepower Extensible Operating System 1
The web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, aka Bug ID CSCux10604.
Cisco
Cisco Firepower 9000 Series Switch Clickjacking Vulnerability
vendor_cisco·2015-11-18·CVSS 5.0
CVE-2015-6374 [MEDIUM] CWE-20 Cisco Firepower 9000 Series Switch Clickjacking Vulnerability
Cisco Firepower 9000 Series Switch Clickjacking Vulnerability
A vulnerability in the web interface of the Cisco Firepower 9000 Series Switch could allow an unauthenticated, remote attacker to affect the integrity of the device though a clickjacking or phishing attack.
The vulnerability is due to the lack of proper input sanitization of iFrame data in the HTTP requests sent to the device. An attacker could exploit this vulnerability by sending crafted HTTP packets with malicious iFrame data. An exploit could allow the attacker to perform a clickjacking or phishing attack where the user is tricked into clicking a malicious link. Protection mechanisms should be used to help prevent this type of attack.
Cisco has not released software updates that address this vulnerability. Workarounds tha
Cisco
Cisco Firepower 9000 Series Switch Clickjacking Vulnerability
vendor_cisco
CVE-2015-6374 Cisco Firepower 9000 Series Switch Clickjacking Vulnerability
CVE-2015-6374: Cisco Firepower 9000 Series Switch Clickjacking Vulnerability
A vulnerability in the web interface of the Cisco Firepower 9000 Series Switch could allow an unauthenticated, remote attacker to affect the integrity of the device though a clickjacking or phishing attack. The vulnerability is due to the lack of proper input sanitization of iFrame data in the HTTP requests sent to the device. An attacker could exploit this vulnerability by sending crafted HTTP packets with malicious iFrame data. An exploit could allow the attacker to perform a clickjacking or phishing attack where the user is tricked into clicking a malicious link. Protection mechanisms should be used to help prevent this type of attack. Cisco has not released software updates that address this vulnerability.
CWE
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-11-19
Published