Svi
Pretraži prema proizvođaču
Pretraži prema CWE oznaci
O usluzi
Pretplate
Jezik
hr
en
CVE-2016-6433 - CERT CVE
CVE-2016-6433
ID
CVE-2016-6433
Sažetak
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary commands via crafted web-application parameters, aka Bug ID CSCva30872.
Reference
http://packetstormsecurity.com/files/140467/Cisco-Firepower-Management-Console-6.0-Post-Authentication-UserAdd.html
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-ftmc
http://www.securityfocus.com/bid/93414
https://blog.korelogic.com/blog/2016/10/10/virtual_appliance_spelunking
https://www.exploit-db.com/exploits/40463/
https://www.exploit-db.com/exploits/41041/
https://www.korelogic.com/Resources/Advisories/KL-001-2016-007.txt
http://packetstormsecurity.com/files/140467/Cisco-Firepower-Management-Console-6.0-Post-Authentication-UserAdd.html
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-ftmc
http://www.securityfocus.com/bid/93414
https://blog.korelogic.com/blog/2016/10/10/virtual_appliance_spelunking
https://www.exploit-db.com/exploits/40463/
https://www.exploit-db.com/exploits/41041/
https://www.korelogic.com/Resources/Advisories/KL-001-2016-007.txt
CVSS
Base:
9.0
Impact:
10.0
Exploitability:
8.0
Pristup
Vektor
Složenost
Autentikacija
NETWORK
LOW
SINGLE
Impact
Povjerljivost
Cjelovitost
Dostupnost
COMPLETE
COMPLETE
COMPLETE
CVSS vektor
AV:N/AC:L/Au:S/C:C/I:C/A:C
Zadnje važnije ažuriranje
26-11-2024 - 16:09
Objavljeno
06-10-2016 - 10:59