CVE-2016-6394
published 2016-09-12CVE-2016-6394: Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web…
PriorityP345critical9.1CVSS 3.0
AVNACLPRNUINSUCHIHAN
EPSS
1.45%
70.4th percentile
Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web sessions via a session identifier, aka Bug ID CSCuz80503.
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firepower_management_center_and_firesight_system | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Firepower Management Center and FireSIGHT System Software Session Fixation Vulnerability
vendor_cisco·2016-09-07·CVSS 5.8
CVE-2016-6394 [MEDIUM] CWE-264 Cisco Firepower Management Center and FireSIGHT System Software Session Fixation Vulnerability
Cisco Firepower Management Center and FireSIGHT System Software Session Fixation Vulnerability
A vulnerability in session identification management functionality of the web-based management interface for Cisco Firepower Management Center and Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to hijack a valid user session.
The vulnerability exists because the affected application does not assign a new session identifier to a user session when a user authenticates to the application. An attacker could exploit this vulnerability by using a hijacked session identifier to connect to the application through the web-based management interface. A successful exploit could allow the attacker to hijack an authenticated user’s browser session.
Cisco has not released so
Cisco
Cisco Firepower Management Center and FireSIGHT System Software Session Fixation Vulnerability
vendor_cisco
CVE-2016-6394 Cisco Firepower Management Center and FireSIGHT System Software Session Fixation Vulnerability
CVE-2016-6394: Cisco Firepower Management Center and FireSIGHT System Software Session Fixation Vulnerability
A vulnerability in session identification management functionality of the web-based management interface for Cisco Firepower Management Center and Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to hijack a valid user session. The vulnerability exists because the affected application does not assign a new session identifier to a user session when a user authenticates to the application. An attacker could exploit this vulnerability by using a hijacked session identifier to connect to the application through the web-based management interface. A successful exploit could allow the attacker to hijack an authenticated user’s browser session. Cisco has not
GHSA
GHSA-gqcc-hr56-mwvj: Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6
ghsa_unreviewed·2022-05-17
CVE-2016-6394 [CRITICAL] GHSA-gqcc-hr56-mwvj: Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6
Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web sessions via a session identifier, aka Bug ID CSCuz80503.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160907-fsmchttp://www.securityfocus.com/bid/92825http://www.securitytracker.com/id/1036757http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160907-fsmchttp://www.securityfocus.com/bid/92825http://www.securitytracker.com/id/1036757
2016-09-12
Published