CERT-In Vulnerability Note
CIVN-2015-0310
Cisco FireSIGHT Management Center GET Request Information Disclosure Vulnerability
Original Issue Date:December 18, 2015
Severity Rating: MEDIUM
Systems Affected
- Cisco FireSIGHT System Software version 4.10.3, 5.2.0, 5.3.0, 5.3.1 and 5.4.0
Overview
A vulnerability has been reported in Cisco FireSIGHT Management Center which could allow an unauthenticated remote attacker to view the sensitive information from the targeted device.
Description
This vulnerability occurs due to improper sanitation of user-supplied input on the affected device. A remote attacker could exploit this vulnerability by sending a special crafted GET request to the affected device to view the sensitive information.
Successful exploitation of this vulnerability could allow a remote attacker to view sensitive information on the affected device.
Solution
Apply appropriate updates as mentioned in CISCO advisory
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151211-fmc
Vendor Information
CISCO
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151211-fmc
References
CISCO
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151211-fmc
CVE Name
CVE-2015-6419
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|