CVE Vulnerabilities

CVE-2015-6427

Published: Dec 18, 2015 | Modified: Dec 07, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Cisco FireSIGHT Management Center allows remote attackers to bypass the HTTP attack detection feature and avoid triggering Snort IDS rules via an SSL session that is mishandled after decryption, aka Bug ID CSCux53437.

Affected Software

Name Vendor Start Version End Version
Firesight_system_software Cisco 5.3.0 (including) 5.3.0 (including)
Firesight_system_software Cisco 5.3.0.1 (including) 5.3.0.1 (including)
Firesight_system_software Cisco 5.3.0.2 (including) 5.3.0.2 (including)
Firesight_system_software Cisco 5.3.1 (including) 5.3.1 (including)
Firesight_system_software Cisco 5.3.1.1 (including) 5.3.1.1 (including)
Firesight_system_software Cisco 5.3.1.2 (including) 5.3.1.2 (including)
Firesight_system_software Cisco 5.3.1.3 (including) 5.3.1.3 (including)
Firesight_system_software Cisco 5.3.1.4 (including) 5.3.1.4 (including)
Firesight_system_software Cisco 5.3.1.5 (including) 5.3.1.5 (including)
Firesight_system_software Cisco 5.3.1.7 (including) 5.3.1.7 (including)
Firesight_system_software Cisco 5.4.0 (including) 5.4.0 (including)
Firesight_system_software Cisco 5.4.0.1 (including) 5.4.0.1 (including)
Firesight_system_software Cisco 5.4.0.4 (including) 5.4.0.4 (including)
Firesight_system_software Cisco 5.4.1 (including) 5.4.1 (including)
Firesight_system_software Cisco 5.4.1.2 (including) 5.4.1.2 (including)
Firesight_system_software Cisco 5.4.1.3 (including) 5.4.1.3 (including)
Firesight_system_software Cisco 5.4.1.4 (including) 5.4.1.4 (including)
Firesight_system_software Cisco 6.0.0 (including) 6.0.0 (including)
Firesight_system_software Cisco 6.0.0.1 (including) 6.0.0.1 (including)
Firesight_system_software Cisco 6.0.1 (including) 6.0.1 (including)

References