CVE-2016-1457

The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 allows remote authenticated users to execute arbitrary commands as root via crafted HTTP requests, aka Bug ID CSCur25513.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cisco:secure_firewall_management_center:4.10.3.9:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_firewall_management_center:5.2.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_firewall_management_center:5.3.0.4:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_firewall_management_center:5.3.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_firewall_management_center:5.4.0:*:*:*:*:*:*:*

History

26 Nov 2024, 16:09

Type Values Removed Values Added
First Time Cisco secure Firewall Management Center
CPE cpe:2.3:a:cisco:firepower_management_center:4.10.3.9:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:5.3.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:5.3.0.4:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:5.4.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:5.2.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_firewall_management_center:5.2.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_firewall_management_center:5.3.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_firewall_management_center:5.3.0.4:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_firewall_management_center:5.4.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_firewall_management_center:4.10.3.9:*:*:*:*:*:*:*

21 Nov 2024, 02:46

Type Values Removed Values Added
References () http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-fmc - Vendor Advisory () http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-fmc - Vendor Advisory
References () http://www.securityfocus.com/bid/92509 - () http://www.securityfocus.com/bid/92509 -
References () http://www.securitytracker.com/id/1036642 - () http://www.securitytracker.com/id/1036642 -

Information

Published : 2016-08-18 19:59

Updated : 2024-11-26 16:09


NVD link : CVE-2016-1457

Mitre link : CVE-2016-1457

CVE.ORG link : CVE-2016-1457


JSON object : View

Products Affected

cisco

  • secure_firewall_management_center
CWE
CWE-264

Permissions, Privileges, and Access Controls