Summary
Detail | |||
---|---|---|---|
Vendor | Cisco | First view | 2015-12-15 |
Product | Secure Firewall Management Center | Last view | 2024-10-23 |
Version | Type | Application | |
Update | |||
Edition | |||
Language | |||
Sofware Edition | |||
Target Software | |||
Target Hardware | |||
Other |
Activity : Overall
COMMON PLATFORM ENUMERATION: Repartition per Version
Related : CVE
Date | Alert | Description | |
---|---|---|---|
6.5 | 2024-10-23 | CVE-2024-20482 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to elevate privileges on an affected device. To exploit this vulnerability, an attacker must have a valid account on the device that is configured with a custom read-only role. This vulnerability is due to insufficient validation of role permissions in part of the web-based management interface. An attacker could exploit this vulnerability by performing a write operation on the affected part of the web-based management interface. A successful exploit could allow the attacker to modify certain parts of the configuration. |
6.5 | 2024-10-23 | CVE-2024-20473 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit this vulnerability, an attacker would need Administrator-level privileges. |
6.5 | 2024-10-23 | CVE-2024-20472 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit this vulnerability, an attacker would need Administrator-level privileges. |
6.5 | 2024-10-23 | CVE-2024-20471 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit this vulnerability, an attacker would need Administrator-level privileges. |
9.9 | 2024-10-23 | CVE-2024-20424 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to insufficient input validation of certain HTTP requests. An attacker could exploit this vulnerability by authenticating to the web-based management interface of an affected device and then sending a crafted HTTP request to the device. A successful exploit could allow the attacker to execute arbitrary commands with root permissions on the underlying operating system of the Cisco FMC device or to execute commands on managed Cisco Firepower Threat Defense (FTD) devices. To exploit this vulnerability, the attacker would need valid credentials for a user account with at least the role of Security Analyst (Read Only). |
6.1 | 2024-10-23 | CVE-2024-20415 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. |
6.1 | 2024-10-23 | CVE-2024-20410 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. |
6.1 | 2024-10-23 | CVE-2024-20409 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. |
5.4 | 2024-10-23 | CVE-2024-20403 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. |
5.3 | 2024-10-23 | CVE-2024-20388 | A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to determine valid user names on an affected device. This vulnerability is due to improper authentication of password update responses. An attacker could exploit this vulnerability by forcing a password reset on an affected device. A successful exploit could allow the attacker to determine valid user names in the unauthenticated response to a forced password reset. |
5.4 | 2024-10-23 | CVE-2024-20387 | A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due to improper input sanitization in the web-based management interface of Cisco FMC Software. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to conduct a stored XSS attack on an affected device. |
6.1 | 2024-10-23 | CVE-2024-20386 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. |
6.5 | 2024-10-23 | CVE-2024-20379 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files on the underlying operating system of the affected device. The attacker would need valid user credentials to exploit this vulnerability. |
5.4 | 2024-10-23 | CVE-2024-20377 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to the web-based management interface not properly validating user-supplied input. An attacker could exploit this vulnerability by by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. |
6.1 | 2024-10-23 | CVE-2024-20372 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. |
5.4 | 2024-10-23 | CVE-2024-20364 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. |
6.5 | 2024-10-23 | CVE-2024-20340 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit this vulnerability, an attacker must have a valid account on the device with the role of Security Approver, Intrusion Admin, Access Admin, or Network Admin. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to read the contents of databases on the affected device and also obtain limited read access to the underlying operating system. |
5.4 | 2024-10-23 | CVE-2024-20300 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. |
5.4 | 2024-10-23 | CVE-2024-20298 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. |
6.1 | 2024-10-23 | CVE-2024-20273 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. |
5.4 | 2024-10-23 | CVE-2024-20269 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. |
5.4 | 2024-10-23 | CVE-2024-20264 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. |
8.8 | 2024-05-22 | CVE-2024-20360 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not adequately validate user input. An attacker could exploit this vulnerability by authenticating to the application and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain any data from the database, execute arbitrary commands on the underlying operating system, and elevate privileges to root. To exploit this vulnerability, an attacker would need at least Read Only user credentials. |
8.8 | 2023-11-01 | CVE-2023-20220 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. To exploit these vulnerabilities, the attacker must have valid device credentials, but does not need Administrator privileges. These vulnerabilities are due to insufficient validation of user-supplied input for certain configuration options. An attacker could exploit these vulnerabilities by using crafted input within the device configuration GUI. A successful exploit could allow the attacker to execute arbitrary commands on the device, including on the underlying operating system, which could also affect the availability of the device. |
8.8 | 2023-11-01 | CVE-2023-20219 | Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The attacker would need valid device credentials but does not require administrator privileges to exploit this vulnerability. These vulnerabilities are due to insufficient validation of user-supplied input for certain configuration options. An attacker could exploit these vulnerabilities by using crafted input within the device configuration GUI. A successful exploit could allow the attacker to execute arbitrary commands on the device including the underlying operating system which could also affect the availability of the device. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
39% (59) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
11% (17) | CWE-20 | Improper Input Validation |
9% (14) | CWE-89 | Improper Sanitization of Special Elements used in an SQL Command ('... |
3% (6) | CWE-693 | Protection Mechanism Failure |
3% (6) | CWE-78 | Improper Sanitization of Special Elements used in an OS Command ('O... |
3% (5) | CWE-400 | Uncontrolled Resource Consumption ('Resource Exhaustion') |
3% (5) | CWE-287 | Improper Authentication |
3% (5) | CWE-200 | Information Exposure |
1% (3) | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path ... |
1% (2) | CWE-798 | Use of Hard-coded Credentials |
1% (2) | CWE-732 | Incorrect Permission Assignment for Critical Resource |
1% (2) | CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') |
1% (2) | CWE-399 | Resource Management Errors |
1% (2) | CWE-319 | Cleartext Transmission of Sensitive Information |
1% (2) | CWE-264 | Permissions, Privileges, and Access Controls |
1% (2) | CWE-77 | Improper Sanitization of Special Elements used in a Command ('Comma... |
0% (1) | CWE-787 | Out-of-bounds Write |
0% (1) | CWE-776 | Unrestricted Recursive Entity References in DTDs ('XML Bomb') |
0% (1) | CWE-772 | Missing Release of Resource after Effective Lifetime |
0% (1) | CWE-770 | Allocation of Resources Without Limits or Throttling |
0% (1) | CWE-755 | Improper Handling of Exceptional Conditions |
0% (1) | CWE-668 | Exposure of Resource to Wrong Sphere |
0% (1) | CWE-611 | Information Leak Through XML External Entity File Disclosure |
0% (1) | CWE-522 | Insufficiently Protected Credentials |
0% (1) | CWE-434 | Unrestricted Upload of File with Dangerous Type |
Snort® IPS/IDS
Date | Description |
---|---|
2020-12-05 | Cisco Firepower User Agent Service default MySQL credentials detected RuleID : 53864 - Type : POLICY-OTHER - Revision : 1 |
2020-12-05 | Cisco Firepower Management Center LDAP authentication bypass attempt RuleID : 52632 - Type : SERVER-WEBAPP - Revision : 3 |
2020-12-05 | Cisco Firepower Management Center LDAP authentication bypass attempt RuleID : 52631 - Type : SERVER-WEBAPP - Revision : 2 |
2020-12-05 | Cisco Firepower Management Center LDAP authentication bypass attempt RuleID : 52630 - Type : SERVER-WEBAPP - Revision : 2 |
2020-12-05 | Cisco Firepower Management Center LDAP authentication bypass attempt RuleID : 52629 - Type : SERVER-WEBAPP - Revision : 3 |
2020-12-05 | Cisco Firepower Management Center LDAP authentication bypass attempt RuleID : 52628 - Type : SERVER-WEBAPP - Revision : 2 |
2020-12-05 | Cisco Firepower Management Center LDAP authentication bypass attempt RuleID : 52627 - Type : SERVER-WEBAPP - Revision : 2 |
2020-12-05 | Cisco Firepower Management Center command injection attempt RuleID : 51719 - Type : SERVER-WEBAPP - Revision : 1 |
2020-12-05 | Cisco Firepower Management Center command injection attempt RuleID : 51718 - Type : SERVER-WEBAPP - Revision : 1 |
2020-12-05 | Cisco Firepower Management Center command injection attempt RuleID : 51717 - Type : SERVER-WEBAPP - Revision : 1 |
2020-12-05 | Cisco Firepower Management Center command injection attempt RuleID : 51716 - Type : SERVER-WEBAPP - Revision : 1 |
2020-12-05 | Cisco Firepower Management Center command injection attempt RuleID : 51711 - Type : SERVER-WEBAPP - Revision : 1 |
2020-12-05 | Cisco Firepower Management Center command injection attempt RuleID : 51710 - Type : SERVER-WEBAPP - Revision : 1 |
2020-12-05 | Cisco Firepower Management Center command injection attempt RuleID : 51709 - Type : SERVER-WEBAPP - Revision : 1 |
2020-12-05 | Cisco Firepower Management Center command injection attempt RuleID : 51708 - Type : SERVER-WEBAPP - Revision : 1 |
2020-12-05 | Cisco Firepower Management Center directory traversal attempt RuleID : 51707 - Type : SERVER-WEBAPP - Revision : 1 |
2020-12-05 | Cisco Firepower Management Center directory traversal attempt RuleID : 51706 - Type : SERVER-WEBAPP - Revision : 1 |
2020-12-05 | Cisco Firepower Management Center directory traversal attempt RuleID : 51705 - Type : SERVER-WEBAPP - Revision : 1 |
2020-12-05 | Cisco Firepower Management Center SQL injection attempt RuleID : 51704 - Type : SERVER-WEBAPP - Revision : 1 |
2020-12-05 | Cisco Firepower Management Center SQL injection attempt RuleID : 51703 - Type : SERVER-WEBAPP - Revision : 1 |
2020-12-05 | Cisco Firepower Management Center SQL injection attempt RuleID : 51702 - Type : SERVER-WEBAPP - Revision : 1 |
2020-12-05 | Cisco Firepower Management Center SQL injection attempt RuleID : 51701 - Type : SERVER-WEBAPP - Revision : 1 |
2020-12-05 | Cisco Firepower Management Center SQL injection attempt RuleID : 51700 - Type : SERVER-WEBAPP - Revision : 1 |
2020-12-05 | Cisco Firepower Management Center SQL injection attempt RuleID : 51699 - Type : SERVER-WEBAPP - Revision : 1 |
2020-12-05 | Cisco Firepower Management Center SQL injection attempt RuleID : 51698 - Type : SERVER-WEBAPP - Revision : 1 |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2018-07-20 | Name: The remote device is missing a vendor-supplied security patch. File: cisco-sa-20180711-firepower.nasl - Type: ACT_GATHER_INFO |
2017-10-12 | Name: The remote device is missing a vendor-supplied security patch. File: cisco-sa-20171004-ftd-firepower_threat_defense.nasl - Type: ACT_GATHER_INFO |
2017-09-13 | Name: A network management application installed on the remote host is affected by ... File: cisco_firepower_mgmt_cntr-sa-20170906-firepower-1_and_2.nasl - Type: ACT_GATHER_INFO |
2017-07-06 | Name: A network management application installed on the remote host is affected by ... File: cisco_firepower_mgmt_cntr-sa-20170621-fmc1_and_fmc2.nasl - Type: ACT_GATHER_INFO |
2017-05-25 | Name: The packet inspection software installed on the remote host is affected by a ... File: cisco-sa-20170405-cfpw.nasl - Type: ACT_GATHER_INFO |
2017-05-25 | Name: The packet inspection software installed on the remote host is affected by a ... File: cisco-sa-20170419-fpsnort.nasl - Type: ACT_GATHER_INFO |
2016-11-02 | Name: The packet inspection software on the remote host is affected by a denial of ... File: cisco-sa-20161019-fpsnort.nasl - Type: ACT_GATHER_INFO |