ID

VAR-201511-0226


CVE

CVE-2015-6374


TITLE

Cisco Firepower 9000 Run on device Firepower Extensible Operating System Vulnerable to a clickjacking attack

Trust: 0.8

sources: JVNDB: JVNDB-2015-005975

DESCRIPTION

The web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, aka Bug ID CSCux10604. The Cisco Firepower 9000 Series Switches are Cisco 9000 Series Switches. A clickjacking vulnerability exists in Cisco Firepower 9000 Series Switches. Allow remote attackers to exploit this vulnerability to compromise affected devices and obtain sensitive information. Other attacks are also possible. This issue being tracked by Cisco Bug ID CSCux10604

Trust: 2.52

sources: NVD: CVE-2015-6374 // JVNDB: JVNDB-2015-005975 // CNVD: CNVD-2015-07738 // BID: 77631 // VULHUB: VHN-84335

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-07738

AFFECTED PRODUCTS

vendor:ciscomodel:firepower extensible operating systemscope:eqversion:1.1\(1.160\)

Trust: 1.6

vendor:ciscomodel:firepower extensible operating systemscope:eqversion:1.1(1.160)

Trust: 0.8

vendor:ciscomodel:firepower extensible operating system on firepower devicesscope:eqversion:1.1(1.160)9000

Trust: 0.6

vendor:ciscomodel:firepower seriesscope:eqversion:90001.1(1.160)

Trust: 0.3

sources: CNVD: CNVD-2015-07738 // BID: 77631 // JVNDB: JVNDB-2015-005975 // CNNVD: CNNVD-201511-314 // NVD: CVE-2015-6374

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-6374
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-6374
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2015-07738
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201511-314
value: MEDIUM

Trust: 0.6

VULHUB: VHN-84335
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-6374
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-07738
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-84335
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2015-07738 // VULHUB: VHN-84335 // JVNDB: JVNDB-2015-005975 // CNNVD: CNNVD-201511-314 // NVD: CVE-2015-6374

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-84335 // JVNDB: JVNDB-2015-005975 // NVD: CVE-2015-6374

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201511-314

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201511-314

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-005975

PATCH

title:cisco-sa-20151117-firepower4url:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151117-firepower4

Trust: 0.8

sources: JVNDB: JVNDB-2015-005975

EXTERNAL IDS

db:NVDid:CVE-2015-6374

Trust: 3.4

db:BIDid:77631

Trust: 1.6

db:JVNDBid:JVNDB-2015-005975

Trust: 0.8

db:CNNVDid:CNNVD-201511-314

Trust: 0.7

db:CNVDid:CNVD-2015-07738

Trust: 0.6

db:SEEBUGid:SSVID-89897

Trust: 0.1

db:VULHUBid:VHN-84335

Trust: 0.1

sources: CNVD: CNVD-2015-07738 // VULHUB: VHN-84335 // BID: 77631 // JVNDB: JVNDB-2015-005975 // CNNVD: CNNVD-201511-314 // NVD: CVE-2015-6374

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20151117-firepower4

Trust: 2.6

url:http://www.securityfocus.com/bid/77631

Trust: 1.2

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-6374

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-6374

Trust: 0.8

url:http://www.cisco.com

Trust: 0.3

sources: CNVD: CNVD-2015-07738 // VULHUB: VHN-84335 // BID: 77631 // JVNDB: JVNDB-2015-005975 // CNNVD: CNNVD-201511-314 // NVD: CVE-2015-6374

CREDITS

Cisco

Trust: 0.9

sources: BID: 77631 // CNNVD: CNNVD-201511-314

SOURCES

db:CNVDid:CNVD-2015-07738
db:VULHUBid:VHN-84335
db:BIDid:77631
db:JVNDBid:JVNDB-2015-005975
db:CNNVDid:CNNVD-201511-314
db:NVDid:CVE-2015-6374

LAST UPDATE DATE

2024-11-23T23:12:37.409000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-07738date:2015-11-24T00:00:00
db:VULHUBid:VHN-84335date:2015-11-19T00:00:00
db:BIDid:77631date:2015-11-17T00:00:00
db:JVNDBid:JVNDB-2015-005975date:2015-11-20T00:00:00
db:CNNVDid:CNNVD-201511-314date:2015-11-19T00:00:00
db:NVDid:CVE-2015-6374date:2024-11-21T02:34:52.840

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-07738date:2015-11-24T00:00:00
db:VULHUBid:VHN-84335date:2015-11-19T00:00:00
db:BIDid:77631date:2015-11-17T00:00:00
db:JVNDBid:JVNDB-2015-005975date:2015-11-20T00:00:00
db:CNNVDid:CNNVD-201511-314date:2015-11-19T00:00:00
db:NVDid:CVE-2015-6374date:2015-11-19T02:59:06.317