CVE-2016-6434
published 2016-10-06CVE-2016-6434: Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive information by leveraging CLI access…
PriorityP341high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EXPLOIT
EPSS
0.98%
58.4th percentile
Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive information by leveraging CLI access, aka Bug ID CSCva30370.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firepower_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-888q-c9pw-cm4h: Cisco Firepower Management Center 6
ghsa_unreviewed·2022-05-17
CVE-2016-6434 [HIGH] CWE-287 GHSA-888q-c9pw-cm4h: Cisco Firepower Management Center 6
Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive information by leveraging CLI access, aka Bug ID CSCva30370.
Cisco
Cisco Firepower Management Center Console Authentication Bypass Vulnerability
vendor_cisco·2016-10-05·CVSS 4.3
CVE-2016-6434 [MEDIUM] CWE-287 Cisco Firepower Management Center Console Authentication Bypass Vulnerability
Cisco Firepower Management Center Console Authentication Bypass Vulnerability
A vulnerability in the web console of Cisco Firepower Management Center could allow an authenticated, local attacker to bypass authentication and access sensitive information.
The vulnerability is due to the use of static credentials by the database on an affected system. An authenticated user who can access the command-line interface (CLI) for an affected system may be able to leverage this vulnerability to access information in the database directly from a local shell.
Cisco has not released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/Cisco
Cisco
Cisco Firepower Management Center Console Authentication Bypass Vulnerability
vendor_cisco
CVE-2016-6434 Cisco Firepower Management Center Console Authentication Bypass Vulnerability
CVE-2016-6434: Cisco Firepower Management Center Console Authentication Bypass Vulnerability
A vulnerability in the web console of Cisco Firepower Management Center could allow an authenticated, local attacker to bypass authentication and access sensitive information. The vulnerability is due to the use of static credentials by the database on an affected system. An authenticated user who can access the command-line interface (CLI) for an affected system may be able to leverage this vulnerability to access information in the database directly from a local shell. Cisco has not released software updates that address this vulnerability. There are no
CWE: CWE-287, CWE-287
Bug IDs: CSCva30370
No detection rules found.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-ftmc1http://www.securityfocus.com/bid/93412https://blog.korelogic.com/blog/2016/10/10/virtual_appliance_spelunkinghttps://www.exploit-db.com/exploits/40465/https://www.korelogic.com/Resources/Advisories/KL-001-2016-005.txthttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-ftmc1http://www.securityfocus.com/bid/93412https://blog.korelogic.com/blog/2016/10/10/virtual_appliance_spelunkinghttps://www.exploit-db.com/exploits/40465/https://www.korelogic.com/Resources/Advisories/KL-001-2016-005.txt
2016-10-06
Published