CVE-2016-1342
published 2016-02-26CVE-2016-1342: The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attackers to obtain potentially sensitive software-version…
PriorityP425medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
1.06%
60.8th percentile
The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attackers to obtain potentially sensitive software-version information by reading help files, aka Bug ID CSCuy36654.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firepower_management_center_unauthenticated | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco FirePOWER Management Center Unauthenticated Information Disclosure Vulnerability
vendor_cisco·2016-02-25·CVSS 5.0
CVE-2016-1342 [MEDIUM] CWE-200 Cisco FirePOWER Management Center Unauthenticated Information Disclosure Vulnerability
Cisco FirePOWER Management Center Unauthenticated Information Disclosure Vulnerability
A vulnerability in the Cisco FirePOWER Management Center could allow an unauthenticated, remote attacker to obtain information about the Cisco FirePOWER Management Center software version from the device login page.
The vulnerability is due to verbose output returned when HTML files are retrieved from the affected system. An attacker could exploit this vulnerability by reading the information disclosed in the help files to conduct further attacks.
Cisco has not released software updates that address this vulnerability. Workarounds that address this vulnerability are not available.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAd
Cisco
Cisco FirePOWER Management Center Unauthenticated Information Disclosure Vulnerability
vendor_cisco
CVE-2016-1342 Cisco FirePOWER Management Center Unauthenticated Information Disclosure Vulnerability
CVE-2016-1342: Cisco FirePOWER Management Center Unauthenticated Information Disclosure Vulnerability
A vulnerability in the Cisco FirePOWER Management Center could allow an unauthenticated, remote attacker to obtain information about the Cisco FirePOWER Management Center software version from the device login page. The vulnerability is due to verbose output returned when HTML files are retrieved from the affected system. An attacker could exploit this vulnerability by reading the information disclosed in the help files to conduct further attacks. Cisco has not released software updates that address this vulnerability.
CWE: CWE-200, CWE-200
Bug IDs: CSCuy36654
GHSA
GHSA-cj62-hc3c-q4gw: The device login page in Cisco FirePOWER Management Center 5
ghsa_unreviewed·2022-05-17
CVE-2016-1342 [MEDIUM] CWE-200 GHSA-cj62-hc3c-q4gw: The device login page in Cisco FirePOWER Management Center 5
The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attackers to obtain potentially sensitive software-version information by reading help files, aka Bug ID CSCuy36654.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-02-26
Published