CVE-2016-6419

HIGH

Cisco Firepower Mgmt Ctr <5.4.0 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in Cisco Firepower Management Center 4.10.3 through 5.4.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCur25485.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93206

Scores

CVSS v3 7.5
EPSS 0.0128
EPSS Percentile 67.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (5)
cisco/secure_firewall_management_center 4.10.3
cisco/secure_firewall_management_center 5.2.0
cisco/secure_firewall_management_center 5.3.0
cisco/secure_firewall_management_center 5.3.1
cisco/secure_firewall_management_center 5.4.0
Published Oct 05, 2016
Tracked Since Feb 18, 2026