CVE-2016-6394

Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web sessions via a session identifier, aka Bug ID CSCuz80503.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
ciscofiresight_system_software
5.2.0
ciscofiresight_system_software
5.2.0.1
ciscofiresight_system_software
5.2.0.2
ciscofiresight_system_software
5.2.0.3
ciscofiresight_system_software
5.2.0.4
ciscofiresight_system_software
5.2.0.5
ciscofiresight_system_software
5.2.0.6
ciscofiresight_system_software
5.2.0.8
ciscofiresight_system_software
5.3.0
ciscofiresight_system_software
5.3.0.1
ciscofiresight_system_software
5.3.0.2
ciscofiresight_system_software
5.3.0.3
ciscofiresight_system_software
5.3.0.4
ciscofiresight_system_software
5.3.0.5
ciscofiresight_system_software
5.3.0.6
ciscofiresight_system_software
5.3.0.7
ciscofiresight_system_software
5.3.1
ciscofiresight_system_software
5.3.1.1
ciscofiresight_system_software
5.3.1.2
ciscofiresight_system_software
5.3.1.3
ciscofiresight_system_software
5.3.1.4
ciscofiresight_system_software
5.3.1.5
ciscofiresight_system_software
5.3.1.7
ciscofiresight_system_software
5.4.0
ciscofiresight_system_software
5.4.0.1
ciscofiresight_system_software
5.4.0.2
ciscofiresight_system_software
5.4.0.3
ciscofiresight_system_software
5.4.0.4
ciscofiresight_system_software
5.4.0.5
ciscofiresight_system_software
5.4.0.6
ciscofiresight_system_software
5.4.1
ciscofiresight_system_software
5.4.1.2
ciscofiresight_system_software
5.4.1.3
ciscofiresight_system_software
5.4.1.4
ciscofiresight_system_software
6.0.0
ciscofiresight_system_software
6.0.0.1
ciscofiresight_system_software
6.0.1
ciscofiresight_system_software
6.1.0
𝑥
= Vulnerable software versions
Common Weakness Enumeration