← Back

CVE-2016-6394

nvd nist
Published: Sep 12, 2016Modified: May 6, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web sessions via a session identifier, aka Bug ID CSCuz80503.

Affected (38)

1 product
Firesight System Software
Configuration A
38 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 5.2.0.1
Version 5.2.0.2
Version 5.2.0.3
Version 5.2.0.4
Version 5.2.0.5
Version 5.2.0.6
Version 5.2.0.8
Version 5.2.0
Version 5.3.0.1
Version 5.3.0.2
Version 5.3.0.3
Version 5.3.0.4
Version 5.3.0.5
Version 5.3.0.6
Version 5.3.0.7
Version 5.3.0
Version 5.3.1.1
Version 5.3.1.2
Version 5.3.1.3
Version 5.3.1.4
Version 5.3.1.5
Version 5.3.1.7
Version 5.3.1
Version 5.4.0.1
Version 5.4.0.2
Version 5.4.0.3
Version 5.4.0.4
Version 5.4.0.5
Version 5.4.0.6
Version 5.4.0
Version 5.4.1.2
Version 5.4.1.3
Version 5.4.1.4
Version 5.4.1
Version 6.0.0.1
Version 6.0.0
Version 6.0.1
Version 6.1.0

Related CWEs

References (6)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.