CVE-2016-6394

EUVD-2016-7317
Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web sessions via a session identifier, aka Bug ID CSCuz80503.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
Affected Products (NVD)
VendorProductVersion
ciscofiresight_system_software
5.2.0
ciscofiresight_system_software
5.2.0.1
ciscofiresight_system_software
5.2.0.2
ciscofiresight_system_software
5.2.0.3
ciscofiresight_system_software
5.2.0.4
ciscofiresight_system_software
5.2.0.5
ciscofiresight_system_software
5.2.0.6
ciscofiresight_system_software
5.2.0.8
ciscofiresight_system_software
5.3.0
ciscofiresight_system_software
5.3.0.1
ciscofiresight_system_software
5.3.0.2
ciscofiresight_system_software
5.3.0.3
ciscofiresight_system_software
5.3.0.4
ciscofiresight_system_software
5.3.0.5
ciscofiresight_system_software
5.3.0.6
ciscofiresight_system_software
5.3.0.7
ciscofiresight_system_software
5.3.1
ciscofiresight_system_software
5.3.1.1
ciscofiresight_system_software
5.3.1.2
ciscofiresight_system_software
5.3.1.3
ciscofiresight_system_software
5.3.1.4
ciscofiresight_system_software
5.3.1.5
ciscofiresight_system_software
5.3.1.7
ciscofiresight_system_software
5.4.0
ciscofiresight_system_software
5.4.0.1
ciscofiresight_system_software
5.4.0.2
ciscofiresight_system_software
5.4.0.3
ciscofiresight_system_software
5.4.0.4
ciscofiresight_system_software
5.4.0.5
ciscofiresight_system_software
5.4.0.6
ciscofiresight_system_software
5.4.1
ciscofiresight_system_software
5.4.1.2
ciscofiresight_system_software
5.4.1.3
ciscofiresight_system_software
5.4.1.4
ciscofiresight_system_software
6.0.0
ciscofiresight_system_software
6.0.0.1
ciscofiresight_system_software
6.0.1
ciscofiresight_system_software
6.1.0
𝑥
= Vulnerable software versions
Common Weakness Enumeration