CVE-2016-6435
published 2016-10-06CVE-2016-6435: The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug ID…
PriorityP355medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EXPLOIT
EPSS
36.62%
98.3th percentile
The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug ID CSCva30376.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firepower_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect HTTP GET requests to /events/reports/view.cgi containing directory traversal sequences (e.g., '../') in the 'files' parameter, especially combined with null-byte (%00) injection. ↗
- →Monitor for HTTP responses with Content-Disposition: attachment and Content-Type: application/octet-stream from /events/reports/view.cgi, which may indicate successful file exfiltration. ↗
- →Alert on authenticated web console requests where the 'files' parameter traverses outside the expected report directory (e.g., contains '..') targeting sensitive OS files. ↗
- →Look for the CGISESSID cookie in requests to /events/reports/view.cgi with traversal payloads as an indicator of authenticated exploitation attempts. ↗
- ·The webserver runs as the 'www' user, limiting file read access — highly privileged files like /etc/shadow are NOT readable via this vulnerability. ↗
- ·Exploitation requires prior authentication to the Firepower Management Center web console; unauthenticated exploitation is not possible. ↗
- ·Affected version is Cisco Fire Linux OS 6.0.1 (build 37/build 1213); the vendor patch is available in version 6.1. ↗
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Firepower Management Center Console Local File Inclusion Vulnerability
vendor_cisco·2016-10-05·CVSS 4.0
CVE-2016-6435 [MEDIUM] CWE-200 Cisco Firepower Management Center Console Local File Inclusion Vulnerability
Cisco Firepower Management Center Console Local File Inclusion Vulnerability
A vulnerability in the web console of Cisco Firepower Management Center could allow an authenticated, remote attacker to access sensitive information.
The vulnerability is due to improper validation of parameters that are sent to the web console of an affected system. The vulnerability could allow an authenticated console user to access files that are readable by the www user on the server. An attacker who has user privileges for the web console could leverage this vulnerability to read some of the files on the underlying operating system.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following l
Cisco
Cisco Firepower Management Center Console Local File Inclusion Vulnerability
vendor_cisco
CVE-2016-6435 Cisco Firepower Management Center Console Local File Inclusion Vulnerability
CVE-2016-6435: Cisco Firepower Management Center Console Local File Inclusion Vulnerability
A vulnerability in the web console of Cisco Firepower Management Center could allow an authenticated, remote attacker to access sensitive information. The vulnerability is due to improper validation of parameters that are sent to the web console of an affected system. The vulnerability could allow an authenticated console user to access files that are readable by the www user on the server. An attacker who has user privileges for the web console could leverage this vulnerability to read some of the files on the underlying operating system. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-200, CWE-200
Bug IDs: CSCva30376
GHSA
GHSA-hqcq-vffg-mcgx: The web console in Cisco Firepower Management Center 6
ghsa_unreviewed·2022-05-17
CVE-2016-6435 [MEDIUM] CWE-200 GHSA-hqcq-vffg-mcgx: The web console in Cisco Firepower Management Center 6
The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug ID CSCva30376.
No detection rules found.
Exploit-DB
Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusion
exploitdb·2016-10-05·CVSS 6.5
CVE-2016-6435 [MEDIUM] Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusion
Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusion
---
KL-001-2016-006 : Cisco Firepower Threat Management Console Local File Inclusion
Title: Cisco Firepower Threat Management Console Local File Inclusion
Advisory ID: KL-001-2016-006
Publication Date: 2016.10.05
Publication URL: https://www.korelogic.com/Resources/Advisories/KL-001-2016-006.txt
1. Vulnerability Details
Affected Vendor: Cisco
Affected Product: Firepower Threat Management Console
Affected Version: Cisco Fire Linux OS 6.0.1 (build 37/build 1213)
Platform: Embedded Linux
CWE Classification: CWE-73: External Control of File Name or Path
Impact: Information Disclosure
Attack vector: HTTP
CVE-ID: CVE-2016-6435
2. Vulnerability Description
An authenticated user can access arbitrary files on the local s
Metasploit
Cisco Firepower Management Console 6.0 Post Auth Report Download Directory Traversal
metasploit
Cisco Firepower Management Console 6.0 Post Auth Report Download Directory Traversal
Cisco Firepower Management Console 6.0 Post Auth Report Download Directory Traversal
This module exploits a directory traversal vulnerability in Cisco Firepower Management under the context of www user. Authentication is required to exploit this vulnerability.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-ftmc2http://www.securityfocus.com/bid/93421https://blog.korelogic.com/blog/2016/10/10/virtual_appliance_spelunkinghttps://www.exploit-db.com/exploits/40464/https://www.korelogic.com/Resources/Advisories/KL-001-2016-006.txthttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-ftmc2http://www.securityfocus.com/bid/93421https://blog.korelogic.com/blog/2016/10/10/virtual_appliance_spelunkinghttps://www.exploit-db.com/exploits/40464/https://www.korelogic.com/Resources/Advisories/KL-001-2016-006.txt
2016-10-06
Published