Vulnerabilities > Cisco > Firesight System Software > 5.4.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2015-12-12 | CVE-2015-6419 | Information Exposure vulnerability in Cisco Firesight System Software Cisco FireSIGHT Management Center with software 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote authenticated users to read arbitrary files via a crafted GET request, aka Bug ID CSCur25410. | 6.8 |
2015-11-18 | CVE-2015-6357 | Improper Input Validation vulnerability in Cisco Firesight System Software The rule-update feature in Cisco FireSIGHT Management Center (MC) 5.2 through 5.4.0.1 does not verify the X.509 certificate of the support.sourcefire.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide an invalid package, and consequently execute arbitrary code, via a crafted certificate, aka Bug ID CSCuw06444. | 6.8 |
2015-10-31 | CVE-2015-6353 | Cross-site Scripting vulnerability in Cisco Firesight System Software Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight Management Center (MC) 5.3.1.5 and 5.4.x through 5.4.1.3 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuu28922. | 3.5 |