CVE-2016-6433
CVE-2016-6433
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary commands via crafted web-application parameters, aka Bug ID CSCva30872.
Affected products
n/a · n/apublic PoCs found — 5
cve_referencepacketstormsecurity.com/files/140467/Cisco-Firepower-Management-Console-6.0-Post-Authentication-UserAdd.htmlunverifiedcve_referencewww.exploit-db.com/exploits/40463/unverifiedcve_referencewww.exploit-db.com/exploits/41041/unverifiedexploitdbwww.exploit-db.com/exploits/40463unverifiedexploitdbwww.exploit-db.com/exploits/41041unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://packetstormsecurity.com/files/140467/Cisco-Firepower-Management-Console-6.0-Post-Authentication-UserAdd.htmlhttps://blog.korelogic.com/blog/2016/10/10/virtual_appliance_spelunkinghttps://www.exploit-db.com/exploits/40463/https://www.exploit-db.com/exploits/41041/https://www.korelogic.com/Resources/Advisories/KL-001-2016-007.txthttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-ftmchttp://www.securityfocus.com/bid/93414