CVE-2015-6419
published 2015-12-12CVE-2015-6419: Cisco FireSIGHT Management Center with software 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote authenticated users to read arbitrary files via a crafted…
PriorityP433medium6.8CVSS 2.0
AVNACLAuSCCINAN
EPSS
1.15%
63.3th percentile
Cisco FireSIGHT Management Center with software 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote authenticated users to read arbitrary files via a crafted GET request, aka Bug ID CSCur25410.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firesight_management_center_get_request | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| libmspack_project | libmspack | >= 0 < 0.4-1ubuntu0.1~esm2 | 0.4-1ubuntu0.1~esm2 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:C/I:N/A:N
osv4.3MEDIUM
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libmspack vulnerabilities
osv·2025-10-01·CVSS 4.3
CVE-2015-4467 libmspack vulnerabilities
libmspack vulnerabilities
Jakub Wilk discovered that libmspack did not correctly handle certain
integer operations and bounds checking. A remote attacker could possibly
use this issue to cause a denial of service. (CVE-2015-4467, CVE-2015-4468,
CVE-2015-4469, CVE-2015-4472)
It was discovered that libmspack incorrectly handled certain malformed CAB
files. A remote attacker could use this issue to cause libmspack to crash,
resulting in a denial of service. (CVE-2017-11423)
It was discovered that libmspack incorrectly handled certain malformed CHM
files. A remote attacker could use this issue to cause libmspack to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2017-6419)
Hanno Böck discovered that libmspack incorrectly handled certain CHM files.
An attac
GHSA
GHSA-f83p-ccx3-r342: Cisco FireSIGHT Management Center with software 4
ghsa_unreviewed·2022-05-17
CVE-2015-6419 [MEDIUM] CWE-200 GHSA-f83p-ccx3-r342: Cisco FireSIGHT Management Center with software 4
Cisco FireSIGHT Management Center with software 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote authenticated users to read arbitrary files via a crafted GET request, aka Bug ID CSCur25410.
Cisco
Cisco FireSIGHT Management Center GET Request Information Disclosure Vulnerability
vendor_cisco·2015-12-11·CVSS 6.8
CVE-2015-6419 [MEDIUM] CWE-200 Cisco FireSIGHT Management Center GET Request Information Disclosure Vulnerability
Cisco FireSIGHT Management Center GET Request Information Disclosure Vulnerability
A vulnerability in the Cisco FireSIGHT Management Center could allow an authenticated, remote attacker to view sensitive information from the underlying operating system.
The vulnerability is due to improper sanitation of user-supplied input. An attacker could exploit this vulnerability by sending special GET requests to a vulnerable device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151211-fmc
Cisco
Cisco FireSIGHT Management Center GET Request Information Disclosure Vulnerability
vendor_cisco
CVE-2015-6419 Cisco FireSIGHT Management Center GET Request Information Disclosure Vulnerability
CVE-2015-6419: Cisco FireSIGHT Management Center GET Request Information Disclosure Vulnerability
A vulnerability in the Cisco FireSIGHT Management Center could allow an authenticated, remote attacker to view sensitive information from the underlying operating system. The vulnerability is due to improper sanitation of user-supplied input. An attacker could exploit this vulnerability by sending special GET requests to a vulnerable device. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-200, CWE-200
Bug IDs: CSCur25410
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-12-12
Published