vendor:
Firepower Threat Management Console
by:
KoreLogic
7,8
CVSS
HIGH
Authentication Bypass
798
CWE
Product Name: Firepower Threat Management Console
Affected Version From: Cisco Fire Linux OS 6.0.1 (build 37/build 1213)
Affected Version To: Cisco Fire Linux OS 6.0.1 (build 37/build 1213)
Patch Exists: YES
Related CWE: CVE-2016-6434
CPE: o:cisco:firepower_threat_management_console
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Embedded Linux
2016
Cisco Firepower Threat Management Console Hard-coded MySQL Credentials
The root account for the local MySQL database of Cisco Firepower Threat Management Console has poor password complexity, allowing an attacker to bypass authentication and gain access to the database.
Mitigation:
Change the hard-coded credentials of the root account for the local MySQL database.