CVE-2016-1457

HIGH

Cisco Firepower Management Center <5.3.1.2-5.4.0.1 - Authenticated RCE

Title source: llm
STIX 2.1

Description

The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 allows remote authenticated users to execute arbitrary commands as root via crafted HTTP requests, aka Bug ID CSCur25513.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036642
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/92509

Scores

CVSS v3 8.8
EPSS 0.0368
EPSS Percentile 88.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (5)
cisco/secure_firewall_management_center 4.10.3.9
cisco/secure_firewall_management_center 5.2.0
cisco/secure_firewall_management_center 5.3.0.4
cisco/secure_firewall_management_center 5.3.1
cisco/secure_firewall_management_center 5.4.0
Published Aug 18, 2016
Tracked Since Feb 18, 2026