The web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, aka Bug ID CSCux10604.
References
Link | Resource |
---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151117-firepower4 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: cisco
Published: 2015-11-19T02:00:00
Updated: 2015-11-19T02:57:01
Reserved: 2015-08-17T00:00:00
Link: CVE-2015-6374
JSON object: View
NVD Information
Status : Analyzed
Published: 2015-11-19T02:59:06.317
Modified: 2015-11-19T17:19:58.167
Link: CVE-2015-6374
JSON object: View
Redhat Information
No data.
CWE