CVE-2016-6419
published 2016-10-05CVE-2016-6419: SQL injection vulnerability in Cisco Firepower Management Center 4.10.3 through 5.4.0 allows remote authenticated users to execute arbitrary SQL commands via…
PriorityP343high7.5CVSS 3.0
AVNACHPRLUINSUCHIHAH
EPSS
1.28%
66.8th percentile
SQL injection vulnerability in Cisco Firepower Management Center 4.10.3 through 5.4.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCur25485.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firepower_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vendor_cisco6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Firepower Management Center SQL Injection Vulnerability
vendor_cisco·2016-09-28·CVSS 6.0
CVE-2016-6419 [MEDIUM] CWE-89 Cisco Firepower Management Center SQL Injection Vulnerability
Cisco Firepower Management Center SQL Injection Vulnerability
A vulnerability in the web framework of the Cisco Firepower Management Center could allow an authenticated, remote attacker to perform SQL injection on the affected device.
The vulnerability is due to a lack of input validation. An attacker could exploit this vulnerability by sending a crafted SQL request to the affected web page. An exploit could allow the attacker to modify the SQL database used by the Firepower Management Center.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160928-fpmc
Cisco
Cisco Firepower Management Center SQL Injection Vulnerability
vendor_cisco
CVE-2016-6419 Cisco Firepower Management Center SQL Injection Vulnerability
CVE-2016-6419: Cisco Firepower Management Center SQL Injection Vulnerability
A vulnerability in the web framework of the Cisco Firepower Management Center could allow an authenticated, remote attacker to perform SQL injection on the affected device. The vulnerability is due to a lack of input validation. An attacker could exploit this vulnerability by sending a crafted SQL request to the affected web page. An exploit could allow the attacker to modify the SQL database used by the Firepower Management Center. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-89, CWE-89
Bug IDs: CSCur25485
GHSA
GHSA-7p76-mrph-qq8g: SQL injection vulnerability in Cisco Firepower Management Center 4
ghsa_unreviewed·2022-05-17
CVE-2016-6419 [HIGH] CWE-89 GHSA-7p76-mrph-qq8g: SQL injection vulnerability in Cisco Firepower Management Center 4
SQL injection vulnerability in Cisco Firepower Management Center 4.10.3 through 5.4.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCur25485.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-10-05
Published