CVE-2016-6411
published 2016-09-24CVE-2016-6411: Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote attackers…
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
0.75%
50.8th percentile
Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote attackers to bypass intended do-not-decrypt settings via a crafted URL, aka Bug ID CSCva50585.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firepower_management_center_and_firesight_system | — | — |
| cisco | firesight_system_software | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-63j8-fpcg-99f3: Cisco Firepower Management Center and FireSIGHT System Software 6
ghsa_unreviewed·2022-05-17
CVE-2016-6411 [HIGH] CWE-20 GHSA-63j8-fpcg-99f3: Cisco Firepower Management Center and FireSIGHT System Software 6
Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote attackers to bypass intended do-not-decrypt settings via a crafted URL, aka Bug ID CSCva50585.
Cisco
Cisco Firepower Management Center and FireSIGHT System Software SSLIinspection Bypass Vulnerability
vendor_cisco·2016-09-21·CVSS 5.0
CVE-2016-6411 [MEDIUM] CWE-20 Cisco Firepower Management Center and FireSIGHT System Software SSLIinspection Bypass Vulnerability
Cisco Firepower Management Center and FireSIGHT System Software SSLIinspection Bypass Vulnerability
A vulnerability in SSL inspection for Cisco Firepower Management Center and Cisco FireSIGHT System software could allow an unauthenticated, remote attacker to bypass configured do-not-decrypt rules in the SSL policy rule set.
The vulnerability is due to lack of verification of the user input parameters within the HTTP URL against the SSL certificate. An attacker could exploit this vulnerability by sending a crafted HTTP URL to the targeted system. An exploit could allow the attacker to bypass configured SSL inspection rules. The SSL inspection do-not-decrypt rule should force a connection to be permanently encrypted.
Cisco has released software updates that address this vulnerability. Work
Cisco
Cisco Firepower Management Center and FireSIGHT System Software SSLIinspection Bypass Vulnerability
vendor_cisco
CVE-2016-6411 Cisco Firepower Management Center and FireSIGHT System Software SSLIinspection Bypass Vulnerability
CVE-2016-6411: Cisco Firepower Management Center and FireSIGHT System Software SSLIinspection Bypass Vulnerability
A vulnerability in SSL inspection for Cisco Firepower Management Center and Cisco FireSIGHT System software could allow an unauthenticated, remote attacker to bypass configured do-not-decrypt rules in the SSL policy rule set. The vulnerability is due to lack of verification of the user input parameters within the HTTP URL against the SSL certificate. An attacker could exploit this vulnerability by sending a crafted HTTP URL to the targeted system. An exploit could allow the attacker to bypass configured SSL inspection rules. The SSL inspection do-not-decrypt rule should force a connection to be permanently encrypted. Cisco has released software updates that address this vulner
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-09-24
Published