CVE-2016-6396
published 2016-09-12CVE-2016-6396: Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1, when certain malware blocking options are enabled, allow remote…
PriorityP428medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
EPSS
1.24%
65.9th percentile
Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1, when certain malware blocking options are enabled, allow remote attackers to bypass malware detection via crafted fields in HTTP headers, aka Bug ID CSCuz44482.
Affected
53 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firepower_management_center_and_firesight_system | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vfvq-9m42-xwvq: Cisco Firepower Management Center before 6
ghsa_unreviewed·2022-05-17
CVE-2016-6396 [MEDIUM] CWE-20 GHSA-vfvq-9m42-xwvq: Cisco Firepower Management Center before 6
Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1, when certain malware blocking options are enabled, allow remote attackers to bypass malware detection via crafted fields in HTTP headers, aka Bug ID CSCuz44482.
Cisco
Cisco Firepower Management Center and FireSIGHT System Software Malware Bypass Vulnerability
vendor_cisco·2016-09-07·CVSS 5.0
CVE-2016-6396 [MEDIUM] CWE-20 Cisco Firepower Management Center and FireSIGHT System Software Malware Bypass Vulnerability
Cisco Firepower Management Center and FireSIGHT System Software Malware Bypass Vulnerability
A vulnerability in the malicious file detection and blocking features of Cisco Firepower Management Center and Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass malware detection mechanisms on an affected system.
The vulnerability is due to improper input validation of fields in HTTP headers. An attacker could exploit this vulnerability by crafting specific file content on a server or persuading a user to click a specific link. A successful exploit could allow the attacker to bypass malicious file detection or blocking policies that are configured for the system, which could allow malware to pass through the system undetected.
Cisco has released software u
Cisco
Cisco Firepower Management Center and FireSIGHT System Software Malware Bypass Vulnerability
vendor_cisco
CVE-2016-6396 Cisco Firepower Management Center and FireSIGHT System Software Malware Bypass Vulnerability
CVE-2016-6396: Cisco Firepower Management Center and FireSIGHT System Software Malware Bypass Vulnerability
A vulnerability in the malicious file detection and blocking features of Cisco Firepower Management Center and Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass malware detection mechanisms on an affected system. The vulnerability is due to improper input validation of fields in HTTP headers. An attacker could exploit this vulnerability by crafting specific file content on a server or persuading a user to click a specific link. A successful exploit could allow the attacker to bypass malicious file detection or blocking policies that are configured for the system, which could allow malware to pass through the system undetected. Cisco has release
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160907-fsss1http://www.securityfocus.com/bid/92826http://www.securitytracker.com/id/1036756http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160907-fsss1http://www.securityfocus.com/bid/92826http://www.securitytracker.com/id/1036756
2016-09-12
Published