CVE-2016-1457
HIGHCisco Firepower Management Center <5.3.1.2-5.4.0.1 - Authenticated RCE
Title source: llmDescription
The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 allows remote authenticated users to execute arbitrary commands as root via crafted HTTP requests, aka Bug ID CSCur25513.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1036642
Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-fmc
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/92509
Scores
CVSS v3
8.8
EPSS
0.0368
EPSS Percentile
88.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-264
Status
published
Products (5)
cisco/secure_firewall_management_center
4.10.3.9
cisco/secure_firewall_management_center
5.2.0
cisco/secure_firewall_management_center
5.3.0.4
cisco/secure_firewall_management_center
5.3.1
cisco/secure_firewall_management_center
5.4.0
Published
Aug 18, 2016
Tracked Since
Feb 18, 2026