CVE-2016-6460 (CNNVD-201611-445)
中文标题:
Cisco Firepower System Software 安全绕过漏洞
英文标题:
A vulnerability in the FTP Representational State Transfer Application Programming Interface (REST A...
漏洞描述
中文描述:
Cisco Firepower System Software是美国思科(Cisco)公司的一款下一代防火墙产品(NGFW)。FTP Representational State Transfer Application Programming Interface(REST API)是其中的一个用于FTP的网络应用程序API。 Cisco Firepower System Software的FTP REST API中存在安全漏洞。远程攻击者可利用该漏洞绕过FTP恶意软件检测规则,通过FTP连接下载恶意软件。
英文描述:
A vulnerability in the FTP Representational State Transfer Application Programming Interface (REST API) for Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass FTP malware detection rules and download malware over an FTP connection. Cisco Firepower System Software is affected when the device has a file policy with malware block configured for FTP connections. More Information: CSCuv36188 CSCuy91156. Known Affected Releases: 5.4.0.2 5.4.1.1 5.4.1.6 6.0.0 6.1.0 6.2.0. Known Fixed Releases: 6.0.0.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| cisco | firesight_system_software | 5.4.0.2 | - | - |
cpe:2.3:a:cisco:firesight_system_software:5.4.0.2:*:*:*:*:*:*:*
|
| cisco | firesight_system_software | 5.4.1.1 | - | - |
cpe:2.3:a:cisco:firesight_system_software:5.4.1.1:*:*:*:*:*:*:*
|
| cisco | firesight_system_software | 5.4.1.6 | - | - |
cpe:2.3:a:cisco:firesight_system_software:5.4.1.6:*:*:*:*:*:*:*
|
| cisco | firesight_system_software | 6.0.0 | - | - |
cpe:2.3:a:cisco:firesight_system_software:6.0.0:*:*:*:*:*:*:*
|
| cisco | firesight_system_software | 6.1.0 | - | - |
cpe:2.3:a:cisco:firesight_system_software:6.1.0:*:*:*:*:*:*:*
|
| cisco | firesight_system_software | 6.2.0 | - | - |
cpe:2.3:a:cisco:firesight_system_software:6.2.0:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2016-6460 |
2025-11-11 15:19:10 | 2025-11-11 07:34:23 |
| NVD | nvd_CVE-2016-6460 |
2025-11-11 14:55:09 | 2025-11-11 07:43:03 |
| CNNVD | cnnvd_CNNVD-201611-445 |
2025-11-11 15:09:44 | 2025-11-11 07:52:47 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 配置错误
- cnnvd_id: 未提取 -> CNNVD-201611-445
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 7.5
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 0 -> 6
- data_sources: ['cve'] -> ['cve', 'nvd']