Vulnerability Bulletins

Cisco FirePOWER Management Center Unauthenticated Information Disclosure Vulnerability

   
Affected software Cisco
 
A vulnerability in the Cisco FirePOWER Management Center could allow an unauthenticated, remote attacker to obtain information about the Cisco FirePOWER Management Center software version from the device login page.The vulnerability is due to verbose output returned when HTML files are retrieved from the affected system. An attacker could exploit this vulnerability by reading the information disclosed in the help files to conduct further attacks.Cisco has not released software updates that

More info:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160224-fmc?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20FirePOWER%20Management%20Center%20Unauthenticated%20Information%20Disc