Vulnerabilities > Cisco > Firepower Management Center
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2016-08-18 | CVE-2016-1458 | Permissions, Privileges, and Access Controls vulnerability in Cisco Firepower Management Center The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 allows remote authenticated users to increase user-account privileges via crafted HTTP requests, aka Bug ID CSCur25483. | 8.8 |
2016-08-18 | CVE-2016-1457 | Permissions, Privileges, and Access Controls vulnerability in Cisco Firepower Management Center The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 allows remote authenticated users to execute arbitrary commands as root via crafted HTTP requests, aka Bug ID CSCur25513. | 8.8 |
2016-06-18 | CVE-2016-1431 | Cross-site Scripting vulnerability in Cisco Firepower Management Center Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCur25516. | 6.1 |
2016-05-28 | CVE-2016-1413 | Code Injection vulnerability in Cisco Firepower Management Center The web interface in Cisco Firepower Management Center 5.4.0 through 6.0.0.1 allows remote authenticated users to modify pages by placing crafted code in a parameter value, aka Bug ID CSCuy76517. | 6.5 |
2016-02-26 | CVE-2016-1342 | Information Exposure vulnerability in Cisco Firepower Management Center The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attackers to obtain potentially sensitive software-version information by reading help files, aka Bug ID CSCuy36654. | 5.3 |