CVE-2016-6365

EUVD-2016-7288
Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.0.2, 5.3.1, and 5.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCur25508 and CSCur25518.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
Affected Products (NVD)
VendorProductVersion
ciscosecure_firewall_management_center
4.10.3
ciscosecure_firewall_management_center
5.2.0
ciscosecure_firewall_management_center
5.3.0
ciscosecure_firewall_management_center
5.3.0.2
ciscosecure_firewall_management_center
5.3.1
ciscosecure_firewall_management_center
5.4.0
𝑥
= Vulnerable software versions