CVE-2015-6427

Cisco FireSIGHT Management Center - HTTP Attack Detection Bypass via SSL Session Mishandling

Title source: llm
STIX 2.1

Description

Cisco FireSIGHT Management Center allows remote attackers to bypass the HTTP attack detection feature and avoid triggering Snort IDS rules via an SSL session that is mishandled after decryption, aka Bug ID CSCux53437.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1034488

Scores

EPSS 0.0173
EPSS Percentile 75.3%

Details

CWE
CWE-254
Status published
Products (20)
cisco/firesight_system_software 5.3.0
cisco/firesight_system_software 5.3.0.1
cisco/firesight_system_software 5.3.0.2
cisco/firesight_system_software 5.3.1
cisco/firesight_system_software 5.3.1.1
cisco/firesight_system_software 5.3.1.2
cisco/firesight_system_software 5.3.1.3
cisco/firesight_system_software 5.3.1.4
cisco/firesight_system_software 5.3.1.5
cisco/firesight_system_software 5.3.1.7
... and 10 more
Published Dec 18, 2015
Tracked Since Feb 18, 2026