Firesight System Software

Vendor:

First CVE: Apr 23, 2015 · Active for 11 years

35
Total CVEs
More Total CVEs than 96% of tracked products
11.7
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Firesight System Software over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 23, 2015
11 years ago
Most Recent CVE
Aug 7, 2017
3,273 days ago

CVE Severity & Scoring

Firesight System Software35 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local1 (2.9%)
Network18 (51.4%)
Unknown16 (45.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (51.4%)
High1 (2.9%)
Unknown16 (45.7%)
User Interaction
None14 (40.0%)
Unknown16 (45.7%)
Required5 (14.3%)
Privileges Required
Low3 (8.6%)
High1 (2.9%)
None15 (42.9%)
Unknown16 (45.7%)

Top CVEs

Signals from CVEs in this product scope (35 CVEs).

35 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web sessions via a session i
Sep 12, 20169.130NONO
Cisco Firepower System Software 6.0.0 through 6.1.0 has a hardcoded account, which allows remote attackers to obtain CLI access by leveraging knowledge of the password, aka Bug ID
Jul 3, 20168.628NONO
Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 4.10.2 through 6.1.0 and Firepower Management Center allows remote attackers to hijack the authen
Oct 5, 20168.826NONO
Cisco FireSIGHT System Software 5.3.0, 5.3.1, 5.4.0, 6.0, and 6.0.1 allows remote attackers to bypass Snort rules via crafted parameters in the header of an HTTP packet, aka Bug ID
Jul 28, 20167.526NONO
Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote attackers to bypass malware protection via crafted fields in
Apr 1, 20167.525NONO
Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote attackers to bypass intended do
Sep 24, 20167.524NONO
Cisco FirePOWER System Software 5.3.x through 5.3.0.6 and 5.4.x through 5.4.0.3 on FirePOWER 7000 and 8000 appliances, and on the Advanced Malware Protection (AMP) for Networks com
May 5, 20167.524NONO
A vulnerability in the Secure Sockets Layer (SSL) Decryption and Inspection feature of Cisco Firepower System Software 5.4.0, 5.4.1, 6.0.0, 6.1.0, 6.2.0, 6.2.1, and 6.2.2 could all
Aug 7, 20177.523NONO
A vulnerability in the web-based management interface of Cisco Firepower Management Center running FireSIGHT System software could allow an authenticated, remote attacker to view t
Dec 14, 20166.523NONO
The policy implementation in Cisco FireSIGHT Management Center 5.3.1.7, 5.4.0.4, and 6.0.0 for VMware allows remote authenticated administrators to bypass intended policy restricti
Oct 25, 20159.023NONO

Exploit Exposure

Signals from CVEs in this product scope (35 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (35 CVEs).

Media Mentions

Signals from CVEs in this product scope (35 CVEs).

Top CNAs Publishing CVEs For Firesight System Software

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.2.217.51.2%00
6.2.127.10.8%00
6.2.037.21.1%00
6.1.077.91.2%00
_6.1.013.70.8%00
6.0.1.117.52.0%00
6.0.1136.81.3%00
6.0.0.187.21.3%00
6.0.0.017.52.0%00
6.0.0206.41.4%00
5.4.1.627.01.9%00
5.4.1.476.41.2%00
5.4.1.386.01.2%00
5.4.1.286.41.2%00
5.4.1.117.51.6%00
5.4.186.51.2%00
5.4.0.657.21.2%00
5.4.0.557.21.2%00
5.4.0.486.71.4%00
5.4.0.367.31.3%00