Cisco / Firesight System Software
35 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2017-6766 | A vulnerability in the Secure Sockets Layer (SSL) Decryption and Inspection feature of Cisco Firepower System Software 5.4.0, 5.4.1, 6.0.0, 6.1.0, 6.2.0, 6.2.1… | HIGH | 7.5 | Aug 7, 2017 |
| CVE-2017-6735 | A vulnerability in the backup and restore functionality of Cisco FireSIGHT System Software could allow an authenticated, local attacker to execute arbitrary co… | MEDIUM | 6.7 | Jul 10, 2017 |
| CVE-2016-9193 | A vulnerability in the malicious file detection and blocking features of Cisco Firepower Management Center and Cisco FireSIGHT System Software could allow an u… | HIGH | 7.5 | Dec 14, 2016 |
| CVE-2016-6471 | A vulnerability in the web-based management interface of Cisco Firepower Management Center running FireSIGHT System software could allow an authenticated, remo… | MEDIUM | 6.5 | Dec 14, 2016 |
| CVE-2016-6460 | A vulnerability in the FTP Representational State Transfer Application Programming Interface (REST API) for Cisco Firepower System Software could allow an unau… | HIGH | 7.5 | Nov 19, 2016 |
| CVE-2016-6417 | Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 4.10.2 through 6.1.0 and Firepower Management Center allows remote attackers… | HIGH | 8.8 | Oct 5, 2016 |
| CVE-2016-6420 | Cisco FireSIGHT System Software 4.10.3 through 5.4.0 in Firepower Management Center allows remote authenticated users to bypass authorization checks and gain p… | MEDIUM | 6.5 | Oct 5, 2016 |
| CVE-2016-6411 | Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote attackers… | HIGH | 7.5 | Sep 24, 2016 |
| CVE-2016-6396 | Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1, when certain malware blocking options are enabled, allow remote attacker… | MEDIUM | 5.3 | Sep 12, 2016 |
| CVE-2016-6395 | Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Management Center before 6.1 and FireSIGHT System Software be… | MEDIUM | 5.4 | Sep 12, 2016 |
| CVE-2016-6394 | Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web ses… | CRITICAL | 9.1 | Sep 12, 2016 |
| CVE-2016-1463 | Cisco FireSIGHT System Software 5.3.0, 5.3.1, 5.4.0, 6.0, and 6.0.1 allows remote attackers to bypass Snort rules via crafted parameters in the header of an HT… | HIGH | 7.5 | Jul 28, 2016 |
| CVE-2016-1394 | Cisco Firepower System Software 6.0.0 through 6.1.0 has a hardcoded account, which allows remote attackers to obtain CLI access by leveraging knowledge of the… | HIGH | 8.6 | Jul 3, 2016 |
| CVE-2016-1368 | Cisco FirePOWER System Software 5.3.x through 5.3.0.6 and 5.4.x through 5.4.0.3 on FirePOWER 7000 and 8000 appliances, and on the Advanced Malware Protection (… | HIGH | 7.5 | May 5, 2016 |
| CVE-2016-1345 | Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote attackers to bypass malware protection v… | HIGH | 7.5 | Apr 1, 2016 |
| CVE-2016-1356 | Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to enumerate… | LOW | 3.7 | Mar 3, 2016 |
| CVE-2016-1355 | Cross-site scripting (XSS) vulnerability in the Device Management UI in the management interface in Cisco FireSIGHT System Software 6.1.0 allows remote attacke… | MEDIUM | 6.1 | Mar 3, 2016 |
| CVE-2016-1294 | Cross-site scripting (XSS) vulnerability in the Management Center in Cisco FireSIGHT System Software 6.0.1 allows remote attackers to inject arbitrary web scri… | MEDIUM | 6.1 | Jan 16, 2016 |
| CVE-2016-1293 | Multiple cross-site scripting (XSS) vulnerabilities in the Management Center in Cisco FireSIGHT System Software 6.0.0 and 6.0.1 allow remote attackers to injec… | MEDIUM | 6.1 | Jan 16, 2016 |
| CVE-2015-6427 | Cisco FireSIGHT Management Center allows remote attackers to bypass the HTTP attack detection feature and avoid triggering Snort IDS rules via an SSL session t… | MEDIUM | 5.0 | Dec 18, 2015 |
| CVE-2015-6419 | Cisco FireSIGHT Management Center with software 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote authenticated users to read arbitrary files via a crafted… | MEDIUM | 6.8 | Dec 12, 2015 |
| CVE-2015-6357 | The rule-update feature in Cisco FireSIGHT Management Center (MC) 5.2 through 5.4.0.1 does not verify the X.509 certificate of the support.sourcefire.com SSL s… | MEDIUM | 6.8 | Nov 18, 2015 |
| CVE-2015-6363 | Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco FireSIGHT Management Center (MC) 5.4.1.4 and 6.0.1 allow remote authenticated… | LOW | 3.5 | Nov 12, 2015 |
| CVE-2015-6354 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight Management Center (MC) 5.4.1.3 and 6.0 allow remote authenticated users to inject arbitr… | LOW | 3.5 | Oct 31, 2015 |
| CVE-2015-6353 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight Management Center (MC) 5.3.1.5 and 5.4.x through 5.4.1.3 allow remote authenticated user… | LOW | 3.5 | Oct 31, 2015 |
Showing 1 to 25 of 35 CVEs