cbcvebase.
CVE-2016-6417
published 2016-10-05

CVE-2016-6417: Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 4.10.2 through 6.1.0 and Firepower Management Center allows remote attackers…

PriorityP339high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
0.63%
46.1th percentile
Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 4.10.2 through 6.1.0 and Firepower Management Center allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCva21636.

Affected

71 ranges· showing 25
VendorProductVersion rangeFixed in
ciscofirepower_management_center_and_firesight_system
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software
ciscofiresight_system_software

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.