Arbitrary Command Execution Vulnerability in Cisco Firepower Management Center and ASA Software (CSCur25513)

Arbitrary Command Execution Vulnerability in Cisco Firepower Management Center and ASA Software (CSCur25513)

CVE-2016-1457 · HIGH Severity

AV:N/AC:L/AU:S/C:C/I:C/A:C

The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 allows remote authenticated users to execute arbitrary commands as root via crafted HTTP requests, aka Bug ID CSCur25513.

Learn more about our Cis Benchmark Audit For Cisco.