Arbitrary Command Execution - CVE-2016-6433
Published: October 5, 2016 / Updated: October 7, 2016
Vulnerability identifier: #VU784
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6433
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote authenticated user to execute arbitrary commands on the target system.
The weakness exists due to insufficient input validation. Sending a specially crafted parameters to the web application an authenticated attacker can access the affected system and execute arbitrary commands.
Successful exploitation of the vulnerability results in arbitrary commands execution on the vulnerable system.
The weakness exists due to insufficient input validation. Sending a specially crafted parameters to the web application an authenticated attacker can access the affected system and execute arbitrary commands.
Successful exploitation of the vulnerability results in arbitrary commands execution on the vulnerable system.
Affected software
How to mitigate CVE-2016-6433
Links to Public Exploits and PoC-codes
- Exploit #414 - Cisco Firepower Threat Management Console 6.0.1 - Remote Command Execution (March 18, 2020)
- Exploit #415 - Cisco Firepower Management Console 6.0 - Post Authentication UserAdd (Metasploit) (March 18, 2020)
- Exploit #1837 - Cisco Firepower Management Console 6.0 Post Authentication UserAdd Vulnerability (March 18, 2020)