6.8

CVE-2015-6357

The rule-update feature in Cisco FireSIGHT Management Center (MC) 5.2 through 5.4.0.1 does not verify the X.509 certificate of the support.sourcefire.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide an invalid package, and consequently execute arbitrary code, via a crafted certificate, aka Bug ID CSCuw06444.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoFiresight System Software Version5.2.0
CiscoFiresight System Software Version5.3.0
CiscoFiresight System Software Version5.3.1.1
CiscoFiresight System Software Version5.3.1.2
CiscoFiresight System Software Version5.3.1.5
CiscoFiresight System Software Version5.4.0
CiscoFiresight System Software Version5.4.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.94% 0.903
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.