Lucene search

K
cveCiscoCVE-2016-1463
HistoryJul 28, 2016 - 1:59 a.m.

CVE-2016-1463

2016-07-2801:59:43
CWE-20
cisco
web.nvd.nist.gov
30
cve-2016-1463
cisco
firesight
system software
remote bypass
snort
http
bug id cscuz20737
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.5

Confidence

High

EPSS

0.003

Percentile

68.3%

Cisco FireSIGHT System Software 5.3.0, 5.3.1, 5.4.0, 6.0, and 6.0.1 allows remote attackers to bypass Snort rules via crafted parameters in the header of an HTTP packet, aka Bug ID CSCuz20737.

Affected configurations

Nvd
Node
ciscofiresight_system_softwareMatch5.3.0
OR
ciscofiresight_system_softwareMatch5.3.1
OR
ciscofiresight_system_softwareMatch5.4.0
OR
ciscofiresight_system_softwareMatch6.0.0
OR
ciscofiresight_system_softwareMatch6.0.1
VendorProductVersionCPE
ciscofiresight_system_software5.3.0cpe:2.3:a:cisco:firesight_system_software:5.3.0:*:*:*:*:*:*:*
ciscofiresight_system_software5.3.1cpe:2.3:a:cisco:firesight_system_software:5.3.1:*:*:*:*:*:*:*
ciscofiresight_system_software5.4.0cpe:2.3:a:cisco:firesight_system_software:5.4.0:*:*:*:*:*:*:*
ciscofiresight_system_software6.0.0cpe:2.3:a:cisco:firesight_system_software:6.0.0:*:*:*:*:*:*:*
ciscofiresight_system_software6.0.1cpe:2.3:a:cisco:firesight_system_software:6.0.1:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.5

Confidence

High

EPSS

0.003

Percentile

68.3%

Related for CVE-2016-1463