CVE-2016-1457

The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 allows remote authenticated users to execute arbitrary commands as root via crafted HTTP requests, aka Bug ID CSCur25513.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cisco:firepower_management_center:4.10.3.9:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:5.2.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:5.3.0.4:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:5.3.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:5.4.0:*:*:*:*:*:*:*

History

21 Nov 2024, 02:46

Type Values Removed Values Added
References () http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-fmc - Vendor Advisory () http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-fmc - Vendor Advisory
References () http://www.securityfocus.com/bid/92509 - () http://www.securityfocus.com/bid/92509 -
References () http://www.securitytracker.com/id/1036642 - () http://www.securitytracker.com/id/1036642 -

Information

Published : 2016-08-18 19:59

Updated : 2024-11-21 02:46


NVD link : CVE-2016-1457

Mitre link : CVE-2016-1457

CVE.ORG link : CVE-2016-1457


JSON object : View

Products Affected

cisco

  • firepower_management_center
CWE
CWE-264

Permissions, Privileges, and Access Controls