A vulnerability in Cisco FirePOWER Management Center could allow an unauthenticated, remote attacker to obtain information about the version of Cisco FirePOWER Management Center software that is running on an affected system. An attacker could use this information to conduct reconnaissance attacks.

The vulnerability is due to verbose output that is returned when the help files are retrieved from an affected system. An attacker could exploit this vulnerability by reading the information disclosed within the help files and potentially conducting further attacks.

Cisco has not released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.

This advisory is available at the following link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-fmc

Leave a Reply