CVE-2016-6435
- EPSS 55.03%
- Published 06.10.2016 10:59:16
- Last modified 12.04.2025 10:46:40
The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug ID CSCva30376.
CVE-2016-6434
- EPSS 0.39%
- Published 06.10.2016 10:59:15
- Last modified 12.04.2025 10:46:40
Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive information by leveraging CLI access, aka Bug ID CSCva30370.
- EPSS 72.6%
- Published 06.10.2016 10:59:14
- Last modified 12.04.2025 10:46:40
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary commands via crafted web-application parameters, aka Bug ID CSCva30872.
CVE-2016-6419
- EPSS 0.54%
- Published 05.10.2016 10:59:19
- Last modified 12.04.2025 10:46:40
SQL injection vulnerability in Cisco Firepower Management Center 4.10.3 through 5.4.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCur25485.
CVE-2016-6365
- EPSS 0.23%
- Published 23.08.2016 02:11:04
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.0.2, 5.3.1, and 5.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCur25508 and CSCur2...
- EPSS 0.2%
- Published 18.08.2016 19:59:02
- Last modified 12.04.2025 10:46:40
The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3....
- EPSS 0.37%
- Published 18.08.2016 19:59:01
- Last modified 12.04.2025 10:46:40
The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4....
CVE-2016-1431
- EPSS 0.25%
- Published 18.06.2016 01:59:01
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCur25516.
CVE-2016-1413
- EPSS 0.18%
- Published 28.05.2016 01:59:02
- Last modified 12.04.2025 10:46:40
The web interface in Cisco Firepower Management Center 5.4.0 through 6.0.0.1 allows remote authenticated users to modify pages by placing crafted code in a parameter value, aka Bug ID CSCuy76517.
CVE-2016-1342
- EPSS 0.23%
- Published 26.02.2016 05:59:01
- Last modified 12.04.2025 10:46:40
The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attackers to obtain potentially sensitive software-version information by reading help files, aka Bug ID CSCuy36654.