Boletines de Vulnerabilidades

Cisco Firepower 9000 Unauthenticated File Access Vulnerability


Información sobre el sistema

   
Software afectado Cisco

Descripción

A vulnerability in the web interface of the Cisco Firepower 9000 Series Switches could allow an unauthenticated, remote attacker to view certain files on the device that should be restricted. The vulnerability is due to lack of proper authentication checks when a request to download and view a file is received. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device.Cisco has not released software updates that address this vulnerability. Workarounds

More info:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151116-firepower?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Firepower%209000%20Unauthenticated%20File%20Access%20Vulnerabili

Identificadores estándar

Propiedad Valor
CVE CVE-2015-6368.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-11-17

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT