CVE-2016-1345
published 2016-04-01CVE-2016-1345: Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote attackers to bypass malware protection…
PriorityP343high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
1.40%
69.4th percentile
Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote attackers to bypass malware protection via crafted fields in HTTP headers, aka Bug ID CSCux22726.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | firepower_malware_block | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Firepower Malware Block Bypass Vulnerability
vendor_cisco·2016-03-30·CVSS 5.0
CVE-2016-1345 [MEDIUM] CWE-20 Cisco Firepower Malware Block Bypass Vulnerability
Cisco Firepower Malware Block Bypass Vulnerability
A vulnerability in the malicious file detection and blocking features of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass malware detection mechanisms on an affected system.
The vulnerability is due to improper input validation of fields in HTTP headers. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to bypass malicious file detection or blocking policies that are configured for the system, which could allow malware to pass through the system undetected.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is
Cisco
Cisco Firepower Malware Block Bypass Vulnerability
vendor_cisco
CVE-2016-1345 Cisco Firepower Malware Block Bypass Vulnerability
CVE-2016-1345: Cisco Firepower Malware Block Bypass Vulnerability
A vulnerability in the malicious file detection and blocking features of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass malware detection mechanisms on an affected system. The vulnerability is due to improper input validation of fields in HTTP headers. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to bypass malicious file detection or blocking policies that are configured for the system, which could allow malware to pass through the system undetected. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-20, CWE-20
Bug IDs: CSCux22726
GHSA
GHSA-xmgp-gw66-397h: Cisco FireSIGHT System Software 5
ghsa_unreviewed·2022-05-17
CVE-2016-1345 [HIGH] CWE-20 GHSA-xmgp-gw66-397h: Cisco FireSIGHT System Software 5
Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote attackers to bypass malware protection via crafted fields in HTTP headers, aka Bug ID CSCux22726.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160330-fphttp://www.securitytracker.com/id/1035437http://www.securitytracker.com/id/1035438http://www.securitytracker.com/id/1035439http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160330-fphttp://www.securitytracker.com/id/1035437http://www.securitytracker.com/id/1035438http://www.securitytracker.com/id/1035439
2016-04-01
Published