cbcvebase.
CVE-2016-1457
published 2016-08-18

CVE-2016-1457: The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software…

PriorityP262high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
3.68%
88.4th percentile
The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 allows remote authenticated users to execute arbitrary commands as root via crafted HTTP requests, aka Bug ID CSCur25513.

Affected

6 ranges
VendorProductVersion rangeFixed in
ciscofirepower_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center

Detection & IOCsextracted from sources · hover to see the quote

  • Detect crafted HTTP requests sent by authenticated users to the Cisco Firepower Management Center web-based GUI that may indicate exploitation of insufficient authorization checking for remote command execution.
  • Monitor for unexpected system command execution running as root originating from the Firepower Management Center web GUI process, which would indicate successful exploitation.
  • Scope detection to authenticated remote users — unauthenticated access is not the attack vector; focus on anomalous privileged activity from logged-in web GUI sessions.
  • ·Vulnerable versions of Cisco Firepower Management Center are 4.x and 5.x before 5.3.1.2, and 5.4.x before 5.4.0.1. Cisco ASA 5500-X with FirePOWER Services is also affected under the same version ranges. Ensure detection/patching scope covers both platforms.
  • ·No workarounds are available for this vulnerability; patching is the only remediation. Detection controls are the sole compensating measure until patching is applied.
  • ·The root cause is insufficient authorization checking in the web GUI, tracked as Bug ID CSCur25513. This means authorization bypass logic — not authentication bypass — is the mechanism; authenticated sessions with low privileges may still trigger the flaw.

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.