CVE-2016-1458
published 2016-08-18CVE-2016-1458: The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 and Cisco Adaptive Security…
PriorityP352high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.40%
82.2th percentile
The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 allows remote authenticated users to increase user-account privileges via crafted HTTP requests, aka Bug ID CSCur25483.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firepower_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hpv8-jm67-hqfq: The web-based GUI in Cisco Firepower Management Center 4
ghsa_unreviewed·2022-05-17
CVE-2016-1458 [HIGH] GHSA-hpv8-jm67-hqfq: The web-based GUI in Cisco Firepower Management Center 4
The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 allows remote authenticated users to increase user-account privileges via crafted HTTP requests, aka Bug ID CSCur25483.
Cisco
Cisco Firepower Management Center Privilege Escalation Vulnerability
vendor_cisco·2016-08-17·CVSS 9.0
CVE-2016-1458 [CRITICAL] CWE-264 Cisco Firepower Management Center Privilege Escalation Vulnerability
Cisco Firepower Management Center Privilege Escalation Vulnerability
A vulnerability in the web-based GUI of Cisco Firepower Management Center and Cisco Adaptive Security Appliance (ASA) 5500-X Series with FirePOWER Services could allow an authenticated, remote attacker to elevate the privileges of user accounts on the affected device.
The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted HTTP requests to the affected device. Successful exploitation could allow an authenticated attacker to elevate the privileges of user accounts configured on the device.
Cisco has released software updates that address this vulnerability. Workarounds that address this vulnerability are not available.
This advisory is available at the
Cisco
Cisco Firepower Management Center Privilege Escalation Vulnerability
vendor_cisco
CVE-2016-1458 Cisco Firepower Management Center Privilege Escalation Vulnerability
CVE-2016-1458: Cisco Firepower Management Center Privilege Escalation Vulnerability
A vulnerability in the web-based GUI of Cisco Firepower Management Center and Cisco Adaptive Security Appliance (ASA) 5500-X Series with FirePOWER Services could allow an authenticated, remote attacker to elevate the privileges of user accounts on the affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted HTTP requests to the affected device. Successful exploitation could allow an authenticated attacker to elevate the privileges of user accounts configured on the device. Cisco has released software updates that address this vulnerability.
CWE: CWE-264, CWE-264
Bug IDs: CSCur25483
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3550 OpenJDK: integer overflows in bytecode streams (Hotspot, 8152479)
bugzilla·2016-07-18·CVSS 4.3
CVE-2016-3550 [MEDIUM] CVE-2016-3550 OpenJDK: integer overflows in bytecode streams (Hotspot, 8152479)
CVE-2016-3550 OpenJDK: integer overflows in bytecode streams (Hotspot, 8152479)
Integer overflow flaws were found in the way the Hotspot component of OpenJDK read bytecode from class files. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions.
Discussion:
Public now via Oracle CPU July 2016, fixed in Oracle JDK 8u101, 7u111, and 6u121.
External References:
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html#AppendixJAVA
---
OpenJDK 8 upstream commit:
http://hg.openjdk.java.net/jdk8u/jdk8u/hotspot/rev/9edc175ff3e6
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2016:1458 https://access.redhat.com/errata/RHSA-2016:1458
---
This i
Bugzilla
CVE-2016-3606 OpenJDK: insufficient bytecode verification (Hotspot, 8155981)
bugzilla·2016-07-15·CVSS 9.6
CVE-2016-3606 [CRITICAL] CVE-2016-3606 OpenJDK: insufficient bytecode verification (Hotspot, 8155981)
CVE-2016-3606 OpenJDK: insufficient bytecode verification (Hotspot, 8155981)
It was discovered that the bytecode verifier in the Hotspot component of OpenJDK did not properly verify correctness of the bytecode in the loaded class files. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions.
Discussion:
Public now via Oracle CPU July 2016, fixed in Oracle JDK 8u101 and 7u111.
External References:
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html#AppendixJAVA
---
OpenJDK 8 upstream commit:
http://hg.openjdk.java.net/jdk8u/jdk8u/hotspot/rev/0095e54dcaa1
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2016:1458 https://access.redhat.com/err
Bugzilla
CVE-2016-3587 OpenJDK: insufficient protection of MethodHandle.invokeBasic() (Hotspot, 8154475)
bugzilla·2016-07-15·CVSS 9.6
CVE-2016-3587 [CRITICAL] CVE-2016-3587 OpenJDK: insufficient protection of MethodHandle.invokeBasic() (Hotspot, 8154475)
CVE-2016-3587 OpenJDK: insufficient protection of MethodHandle.invokeBasic() (Hotspot, 8154475)
It was discovered that the Hotspot component of OpenJDK did not properly restrict access to the invokeBasic() method of the MethodHandle class. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions.
Discussion:
Public now via Oracle CPU July 2016, fixed in Oracle JDK 8u101.
External References:
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html#AppendixJAVA
---
OpenJDK 8 upstream commit:
http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/c387bd2fb7db
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2016:1458 https://access.redhat.com/errata/RHSA-20
2016-08-18
Published