Boletines de Vulnerabilidades |
Cisco FireSIGHT Management Center SSL HTTP Attack Detection Vulnerability |
|
| Software afectado | Cisco |
|
A vulnerability in HTTP attack detection within decrypted SSL traffic of Cisco FireSIGHT Management Center could allow an unauthenticated, remote attacker to bypass HTTP attack detection. The traffic is SSL and the application is configured to decrypt the SSL connection and detect HTTP-based attacks that are associated with Snort intrusion detection rules.The vulnerability is due to improper HTTP attack detection of decrypted SSL connections. An attacker could exploit this vulnerability by More info: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151217-fsm?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20FireSIGHT%20Management%20Center%20SSL%20HTTP%20Attack%20Detection%20Vu |
|














