Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive information by leveraging CLI access, aka Bug ID CSCva30370.Referenceshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-ftmc1https://www.korelogic.com/Resources/Advisories/KL-001-2016-005.txthttps://blog.korelogic.com/blog/2016/10/10/virtual_appliance_spelunkinghttp://www.securityfocus.com/bid/93412https://www.exploit-db.com/exploits/40465/