CVE-2015-6411
published 2015-12-15CVE-2015-6411: Cisco FirePOWER Management Center 5.4.1.3, 6.0.0, and 6.0.1 provides verbose responses to requests for help files, which allows remote attackers to obtain…
PriorityP423medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.20%
64.6th percentile
Cisco FirePOWER Management Center 5.4.1.3, 6.0.0, and 6.0.1 provides verbose responses to requests for help files, which allows remote attackers to obtain potentially sensitive version information by reading an unspecified field, aka Bug ID CSCux37061.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firepower_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco FirePOWER Management Center Software Version Information Disclosure Vulnerability
vendor_cisco·2015-12-09·CVSS 5.0
CVE-2015-6411 [MEDIUM] CWE-200 Cisco FirePOWER Management Center Software Version Information Disclosure Vulnerability
Cisco FirePOWER Management Center Software Version Information Disclosure Vulnerability
A vulnerability in Cisco FirePOWER Management Center could allow an unauthenticated, remote attacker to obtain information about the version of Cisco FirePOWER Management Center software that is running on an affected system. An attacker could use this information to conduct reconnaissance attacks.
The vulnerability is due to verbose output that is returned when the help files are retrieved from an affected system. An attacker could exploit this vulnerability by reading the information disclosed within the help files and potentially conducting further attacks.
Cisco has not released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.
This adv
Cisco
Cisco FirePOWER Management Center Software Version Information Disclosure Vulnerability
vendor_cisco
CVE-2015-6411 Cisco FirePOWER Management Center Software Version Information Disclosure Vulnerability
CVE-2015-6411: Cisco FirePOWER Management Center Software Version Information Disclosure Vulnerability
A vulnerability in Cisco FirePOWER Management Center could allow an unauthenticated, remote attacker to obtain information about the version of Cisco FirePOWER Management Center software that is running on an affected system. An attacker could use this information to conduct reconnaissance attacks. The vulnerability is due to verbose output that is returned when the help files are retrieved from an affected system. An attacker could exploit this vulnerability by reading the information disclosed within the help files and potentially conducting further attacks. Cisco has not released software updates that address this vulnerability. There are no
CWE: CWE-200, CWE-200
Bug IDs: CSCux37061
GHSA
GHSA-5cw8-c36x-qfch: Cisco FirePOWER Management Center 5
ghsa_unreviewed·2022-05-17
CVE-2015-6411 [MEDIUM] CWE-200 GHSA-5cw8-c36x-qfch: Cisco FirePOWER Management Center 5
Cisco FirePOWER Management Center 5.4.1.3, 6.0.0, and 6.0.1 provides verbose responses to requests for help files, which allows remote attackers to obtain potentially sensitive version information by reading an unspecified field, aka Bug ID CSCux37061.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-12-15
Published