CVE-2016-6433
published 2016-10-06CVE-2016-6433: The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary commands via…
PriorityP278high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EXPLOIT
EPSS
75.75%
99.5th percentile
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary commands via crafted web-application parameters, aka Bug ID CSCva30872.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firepower_threat_management | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect POST requests to /DetectionPolicy/rules/rulesimport.cgi with the no_mojo=1 query parameter, especially with multipart/form-data bodies containing shell script filenames or useradd commands. ↗
- →Alert on multipart file upload payloads to rulesimport.cgi where the uploaded file content contains 'useradd' or 'openssl passwd' shell commands. ↗
- →Monitor for new user account creation in the 'ldapgroup' group on Firepower appliances, which is the group used by the exploit to add backdoor accounts. ↗
- →Inspect CGISESSID cookie values in requests to rulesimport.cgi; the exploit requires a valid authenticated session cookie to operate. ↗
- →Look for uploaded filenames matching shell script patterns (e.g., *.sh or Sourcefire_Rule_Update-*.sh) in multipart uploads to rulesimport.cgi, as the exploit disguises the payload as a rule update file. ↗
- →Monitor for SSH logins from newly created accounts immediately following POST requests to rulesimport.cgi, indicating successful backdoor account creation and lateral movement. ↗
- →Detect version fingerprinting requests to /img/favicon.png?v=6.0.1-1213, which the Metasploit module uses to confirm the vulnerable target version before exploitation. ↗
- →Alert on 'sudo su -' execution from non-standard user accounts on Firepower appliances, indicating privilege escalation after backdoor account SSH login. ↗
- ·The exploit requires prior authentication; default credentials (admin:Admin123) are hardcoded in the Metasploit module and should be changed immediately on all deployments. ↗
- ·The vulnerability is exploitable because the www user is permitted to sudo commands (including useradd) as root with no password, making sudo misconfiguration a key contributing factor. ↗
- ·A valid CSRF token (sf_action_id) is required in addition to a valid session, meaning the exploit must first perform a GET to rulesimport.cgi to harvest the token before the malicious POST. ↗
- ·The exploit payload path is rewritten from /tmp to /usr/tmp due to filesystem constraints on the appliance; detection rules targeting /tmp for payload staging will miss this exploit. ↗
- ·Affected versions span Cisco Firepower Management Center 5.2.0 through 6.0.1; the Metasploit module specifically targets build 1213 of 6.0.1. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Firepower Threat Management Console Remote Command Execution Vulnerability
vendor_cisco·2016-10-05·CVSS 6.8
CVE-2016-6433 [MEDIUM] CWE-20 Cisco Firepower Threat Management Console Remote Command Execution Vulnerability
Cisco Firepower Threat Management Console Remote Command Execution Vulnerability
A vulnerability in Cisco Firepower Threat Management Console could allow an authenticated, remote attacker to execute arbitrary commands on a targeted system.
The vulnerability exists because parameters sent to the web application are not properly validated. This may lead an authenticated web user to run arbitrary system commands as the www user account on the server. An attacker with user privileges on the web application may be able to leverage this vulnerability to gain access to the underlying operating system.
Cisco has released software updates that address this vulnerability. Workarounds that address this vulnerability are not available.
This advisory is available at the following link: https://sec.
Cisco
Cisco Firepower Threat Management Console Remote Command Execution Vulnerability
vendor_cisco
CVE-2016-6433 Cisco Firepower Threat Management Console Remote Command Execution Vulnerability
CVE-2016-6433: Cisco Firepower Threat Management Console Remote Command Execution Vulnerability
A vulnerability in Cisco Firepower Threat Management Console could allow an authenticated, remote attacker to execute arbitrary commands on a targeted system. The vulnerability exists because parameters sent to the web application are not properly validated. This may lead an authenticated web user to run arbitrary system commands as the www user account on the server. An attacker with user privileges on the web application may be able to leverage this vulnerability to gain access to the underlying operating system. Cisco has released software updates that address this vulnerability.
CWE: CWE-20, CWE-20
Bug IDs: CSCva30872
GHSA
GHSA-vj79-frfw-249q: The Threat Management Console in Cisco Firepower Management Center 5
ghsa_unreviewed·2022-05-13
CVE-2016-6433 [HIGH] CWE-20 GHSA-vj79-frfw-249q: The Threat Management Console in Cisco Firepower Management Center 5
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary commands via crafted web-application parameters, aka Bug ID CSCva30872.
No detection rules found.
Exploit-DB
Cisco Firepower Management Console 6.0 - Post Authentication UserAdd (Metasploit)
exploitdb·2017-01-13
CVE-2016-6433 Cisco Firepower Management Console 6.0 - Post Authentication UserAdd (Metasploit)
Cisco Firepower Management Console 6.0 - Post Authentication UserAdd (Metasploit)
---
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class MetasploitModule "Cisco Firepower Management Console 6.0 Post Authentication UserAdd Vulnerability",
'Description' => %q{
This module exploits a vulnerability found in Cisco Firepower Management Console.
The management system contains a configuration flaw that allows the www user to
execute the useradd binary, which can be abused to create backdoor accounts.
Authentication is required to exploit this vulnerability.
},
'License' => MSF_LICENSE,
'Author' =>
[
'Matt', # Original discovery & PoC
'sinn3r' # Metasploit module
],
'References' =>
[
[
Exploit-DB
Cisco Firepower Threat Management Console 6.0.1 - Remote Command Execution
exploitdb·2016-10-05·CVSS 8.8
CVE-2016-6433 [HIGH] Cisco Firepower Threat Management Console 6.0.1 - Remote Command Execution
Cisco Firepower Threat Management Console 6.0.1 - Remote Command Execution
---
KL-001-2016-007 : Cisco Firepower Threat Management Console Remote Command
Execution Leading to Root Access
Title: Cisco Firepower Threat Management Console Remote Command Execution
Leading to Root Access
Advisory ID: KL-001-2016-007
Publication Date: 2016.10.05
Publication URL: https://www.korelogic.com/Resources/Advisories/KL-001-2016-007.txt
1. Vulnerability Details
Affected Vendor: Cisco
Affected Product: Firepower Threat Management Console
Affected Version: Cisco Fire Linux OS 6.0.1 (build 37/build 1213)
Platform: Embedded Linux
CWE Classification: CWE-434: Unrestricted Upload of File with Dangerous
Type, CWE-94: Improper Control of Generation of Code
Impact: Arbitrary Code Execution
Attack vector: HT
Metasploit
Cisco Firepower Management Console 6.0 Post Authentication UserAdd Vulnerability
metasploit
Cisco Firepower Management Console 6.0 Post Authentication UserAdd Vulnerability
Cisco Firepower Management Console 6.0 Post Authentication UserAdd Vulnerability
This module exploits a vulnerability found in Cisco Firepower Management Console. The management system contains a configuration flaw that allows the www user to execute the useradd binary, which can be abused to create backdoor accounts. Authentication is required to exploit this vulnerability.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/140467/Cisco-Firepower-Management-Console-6.0-Post-Authentication-UserAdd.htmlhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-ftmchttp://www.securityfocus.com/bid/93414https://blog.korelogic.com/blog/2016/10/10/virtual_appliance_spelunkinghttps://www.exploit-db.com/exploits/40463/https://www.exploit-db.com/exploits/41041/https://www.korelogic.com/Resources/Advisories/KL-001-2016-007.txthttp://packetstormsecurity.com/files/140467/Cisco-Firepower-Management-Console-6.0-Post-Authentication-UserAdd.htmlhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-ftmchttp://www.securityfocus.com/bid/93414https://blog.korelogic.com/blog/2016/10/10/virtual_appliance_spelunkinghttps://www.exploit-db.com/exploits/40463/https://www.exploit-db.com/exploits/41041/https://www.korelogic.com/Resources/Advisories/KL-001-2016-007.txt
2016-10-06
Published