Session fixation in Cisco FireSIGHT - CVE-2016-6394
Published: September 12, 2016 / Updated: September 13, 2016
Cisco FireSIGHT
Detailed vulnerability description
The vulnerability exists due to web application uses previously generated session identifiers when the victim logs in to the application. A remote attacker can perform a session fixation attack and hijack target user's session.
Successful exploitation of this vulnerability may result in hijacking of valid user's browser session.How to mitigate CVE-2016-6394
Cybersecurity Help is currently unaware of any official patch, which addresses this vulnerability.