Vulnerabilities > Cisco > Secure Firewall Management Center > 6.0.0

DATE CVE VULNERABILITY TITLE RISK
2017-10-05 CVE-2017-12244 Improper Input Validation vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the detection engine parsing of IPv6 packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause high CPU utilization or to cause a denial of service (DoS) condition because the Snort process restarts unexpectedly.
network
low complexity
cisco CWE-20
8.6
2017-07-04 CVE-2017-6717 Cross-site Scripting vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface.
network
low complexity
cisco CWE-79
5.4
2017-04-20 CVE-2016-6368 Resource Management Errors vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the detection engine parsing of Pragmatic General Multicast (PGM) protocol packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the Snort process unexpectedly restarting.
network
low complexity
cisco CWE-399
8.6
2017-04-07 CVE-2017-3885 Resource Exhaustion vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the detection engine reassembly of Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the Snort process consumes a high level of CPU resources.
network
high complexity
cisco CWE-400
5.9
2017-02-03 CVE-2017-3814 Improper Input Validation vulnerability in Cisco Secure Firewall Management Center
A vulnerability in Cisco Firepower System Software could allow an unauthenticated, remote attacker to maliciously bypass the appliance's ability to block certain web content, aka a URL Bypass.
network
low complexity
cisco CWE-20
5.8
2016-12-14 CVE-2016-9193 Improper Input Validation vulnerability in Cisco products
A vulnerability in the malicious file detection and blocking features of Cisco Firepower Management Center and Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass malware detection mechanisms on an affected system.
network
low complexity
cisco CWE-20
7.5
2016-10-27 CVE-2016-6439 Resource Management Errors vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the detection engine reassembly of HTTP packets for Cisco Firepower System Software before 6.0.1 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the Snort process unexpectedly restarting.
network
low complexity
cisco CWE-399
7.5
2016-02-26 CVE-2016-1342 Information Exposure vulnerability in Cisco Secure Firewall Management Center
The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attackers to obtain potentially sensitive software-version information by reading help files, aka Bug ID CSCuy36654.
network
low complexity
cisco CWE-200
5.3