
CVE-2016-6417
https://notcve.org/view.php?id=CVE-2016-6417
05 Oct 2016 — Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 4.10.2 through 6.1.0 and Firepower Management Center allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCva21636. Vulnerabilidad de CSRF en Cisco FireSIGHT System Software 4.10.2 hasta la versión 6.1.0 y Firepower Management Center permite a atacantes remotos secuestrar la autenticación de usuarios arbitrarios, vulnerabilidad también conocida como Bug ID CSCva21636. • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160928-fmc • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2016-6420
https://notcve.org/view.php?id=CVE-2016-6420
05 Oct 2016 — Cisco FireSIGHT System Software 4.10.3 through 5.4.0 in Firepower Management Center allows remote authenticated users to bypass authorization checks and gain privileges via a crafted HTTP request, aka Bug ID CSCur25467. Cisco FireSIGHT System Software 4.10.3 hasta la versión 5.4.0 en Firepower Management Center permite a usuarios remotos autenticados eludir comprobaciones de autorización y obtener privilegios a través de una petición HTTP manipulada, vulnerabilidad también conocida como Bug ID CSCur25467. • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160928-fmc1 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-6394
https://notcve.org/view.php?id=CVE-2016-6394
12 Sep 2016 — Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web sessions via a session identifier, aka Bug ID CSCuz80503. Vulnerabilidad de fijación de sesión en Cisco Firepower Management Center y Cisco FireSIGHT System Software hasta la versión 6.1.0 permite a atacantes remotos secuestrar sesiones web a través de un identificador de sesión, vulnerabilidad también conocida como Bug ID CSCuz80503. • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160907-fsmc • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-6395
https://notcve.org/view.php?id=CVE-2016-6395
12 Sep 2016 — Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuz58658. Vulnerabilidad de XSS en la interfaz de administración basada en web en Cisco Firepower Management Center en versiones anteriores a 6.1 y FireSIGHT System Software en versiones anteriores a 6.1 permite a usuarios remotos autentic... • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160907-fsss • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-6396
https://notcve.org/view.php?id=CVE-2016-6396
12 Sep 2016 — Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1, when certain malware blocking options are enabled, allow remote attackers to bypass malware detection via crafted fields in HTTP headers, aka Bug ID CSCuz44482. Cisco Firepower Management Center en versiones anteriores a 6.1 y FireSIGHT System Software en versiones anteriores a 6.1, permite a atacantes remotos, cuando ciertas opciones de bloqueo de malware están habilitadas, eludir la detección de malware a través de camp... • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160907-fsss1 • CWE-20: Improper Input Validation •

CVE-2016-1463
https://notcve.org/view.php?id=CVE-2016-1463
28 Jul 2016 — Cisco FireSIGHT System Software 5.3.0, 5.3.1, 5.4.0, 6.0, and 6.0.1 allows remote attackers to bypass Snort rules via crafted parameters in the header of an HTTP packet, aka Bug ID CSCuz20737. Cisco FireSIGHT System Software 5.3.0, 5.3.1, 5.4.0, 6.0 y 6.0.1 permite a atacantes remotos eludir reglas Snort a través de parámetros manipulados en la cabecera de un paquete HTTP, también conocido como Bug ID CSCuz20737. • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160727-firesight • CWE-20: Improper Input Validation •

CVE-2016-1368
https://notcve.org/view.php?id=CVE-2016-1368
05 May 2016 — Cisco FirePOWER System Software 5.3.x through 5.3.0.6 and 5.4.x through 5.4.0.3 on FirePOWER 7000 and 8000 appliances, and on the Advanced Malware Protection (AMP) for Networks component on these appliances, allows remote attackers to cause a denial of service (packet-processing outage) via crafted packets, aka Bug ID CSCuu86214. Cisco FirePOWER System Software 5.3.x hasta la versión 5.3.0.6 y 5.4.x hasta la versión 5.4.0.3 sobre dispositivos FirePOWER 7000 y 8000 y sobre el componente Advanced Malware Prot... • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160504-firepower • CWE-399: Resource Management Errors •

CVE-2015-6427
https://notcve.org/view.php?id=CVE-2015-6427
18 Dec 2015 — Cisco FireSIGHT Management Center allows remote attackers to bypass the HTTP attack detection feature and avoid triggering Snort IDS rules via an SSL session that is mishandled after decryption, aka Bug ID CSCux53437. Cisco FireSIGHT Management Center permite a atacantes remotos eludir la funcionalidad de detección de ataques HTTP y evitar desencadenar las reglas del IDS Snort a través de una sesión SSL que no es manejada adecuadamente después del desencritado, también conocido como Bug ID CSCux53437. • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151217-fsm • CWE-254: 7PK - Security Features •

CVE-2015-6419
https://notcve.org/view.php?id=CVE-2015-6419
12 Dec 2015 — Cisco FireSIGHT Management Center with software 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote authenticated users to read arbitrary files via a crafted GET request, aka Bug ID CSCur25410. Cisco FireSIGHT Management Center con software 4.10.3, 5.2.0, 5.3.0, 5.3.1 y 5.4.0 permite a usuarios remotos autenticados leer archivos arbitrarios a través de una petición GET manipulada, también conocida como Bug ID CSCur25410. • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151211-fmc • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2015-6357 – Cisco FireSIGHT Management Center Certificate Validation
https://notcve.org/view.php?id=CVE-2015-6357
17 Nov 2015 — The rule-update feature in Cisco FireSIGHT Management Center (MC) 5.2 through 5.4.0.1 does not verify the X.509 certificate of the support.sourcefire.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide an invalid package, and consequently execute arbitrary code, via a crafted certificate, aka Bug ID CSCuw06444. La funcionalidad de actualización de reglas en Cisco FireSIGHT Management Center (MC) 5.2 hasta la versión 5.4.0.1 no verifica el certificado X.509 del servidor ... • https://packetstorm.news/files/id/134390 • CWE-20: Improper Input Validation •