VendorsCiscosecure_firewall_management_center6.2.3
Vulnerabilities

Cisco Secure Firewall Management Center 6.2.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

62CVEs
CVE-2024-20424
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to insufficient input validation of certain HTTP requests. An attacker could exploit this vulnerability by authenticating to the web-based management interface of an affected device and then sending a crafted HTTP request to the device. A successful exploit could allow the attacker to execute arbitrary commands with root permissions on the underlying operating system of the Cisco FMC device or to execute commands on managed Cisco Firepower Threat Defense (FTD) devices. To exploit this vulnerability, the attacker would need valid credentials for a user account with at least the role of Security Analyst (Read Only).
Published 2024-10-23 · Analyzed
9.9EPSS 0.009
CVE-2020-3318
Cisco Firepower Management Center Static Credential Vulnerabilities
Published 2020-05-06 · Modified
9.8EPSS 0.010
CVE-2019-12687
Cisco Firepower Management Center Remote Code Execution Vulnerability
Published 2019-10-02 · Modified
9.0EPSS 0.033
CVE-2019-12683
Cisco Firepower Management Center SQL Injection Vulnerabilities
Published 2019-10-02 · Modified
9.0EPSS 0.030
CVE-2019-12680
Cisco Firepower Management Center SQL Injection Vulnerabilities
Published 2019-10-02 · Modified
9.0EPSS 0.030
CVE-2019-12686
Cisco Firepower Management Center SQL Injection Vulnerabilities
Published 2019-10-02 · Modified
9.0EPSS 0.030
CVE-2019-12684
Cisco Firepower Management Center SQL Injection Vulnerabilities
Published 2019-10-02 · Modified
9.0EPSS 0.030
CVE-2018-0365
A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions on the targeted device via a web browser and with the privileges of the user. Cisco Bug IDs: CSCvb19750.
Published 2018-06-21 · Modified
8.8EPSS 0.009
CVE-2018-0383
A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass a file policy that is configured to block the transfer of files to an affected system via FTP. The vulnerability exists because the affected software incorrectly handles FTP control connections. An attacker could exploit this vulnerability by sending a maliciously crafted FTP connection to transfer a file to an affected device. A successful exploit could allow the attacker to bypass a file policy that is configured to apply the Block upload with reset action to FTP traffic. Cisco Bug IDs: CSCvh70130.
Published 2018-07-16 · Modified
8.6EPSS 0.030
CVE-2020-3499
Cisco Firepower Management Center Software Denial of Service Vulnerability
Published 2020-10-21 · Modified
8.6EPSS 0.020
CVE-2020-3301
Cisco Firepower Management Center Static Credential Vulnerabilities
Published 2020-05-06 · Modified
8.1EPSS 0.008
CVE-2018-15458
Cisco Firepower Management Center Disk Utilization Denial of Service Vulnerability
Published 2019-01-10 · Modified
7.5EPSS 0.031
CVE-2018-0385
A vulnerability in the detection engine parsing of Security Socket Layer (SSL) protocol packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the Snort process unexpectedly restarting. The vulnerability is due to improper input handling of the SSL traffic. An attacker could exploit this vulnerability by sending a crafted SSL traffic to the detection engine on the targeted device. An exploit could allow the attacker to cause a DoS condition if the Snort process restarts and traffic inspection is bypassed or traffic is dropped. Cisco Bug IDs: CSCvi36434.
Published 2018-07-16 · Modified
7.5EPSS 0.023
CVE-2019-1832
Cisco Firepower Threat Defense Software Detection Engine Policy Bypass Vulnerability
Published 2019-05-16 · Modified
7.5EPSS 0.016
CVE-2020-3312
Cisco Firepower Threat Defense Software Information Disclosure Vulnerability
Published 2020-05-06 · Modified
7.5EPSS 0.011
CVE-2018-0278
A vulnerability in the management console of Cisco Firepower System Software could allow an unauthenticated, remote attacker to access sensitive data about the system. The vulnerability is due to improper cross-origin domain protections for the WebSocket protocol. An attacker could exploit this vulnerability by convincing a user to visit a malicious website designed to send requests to the affected application while the user is logged into the application with an active session cookie. A successful exploit could allow the attacker to retrieve policy or configuration information from the affected software and to perform another attack against the management console. Cisco Bug IDs: CSCvh68311.
Published 2018-05-02 · Modified
6.5EPSS 0.021
CVE-2024-20471
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit this vulnerability, an attacker would need Administrator-level privileges.
Published 2024-10-23 · Analyzed
6.5EPSS 0.004
CVE-2025-20301
Cisco Secure Firewall Management Center Software Authorization Bypass Vulnerability
Published 2025-08-14 · Analyzed
6.5EPSS 0.004
CVE-2019-1642
Cisco Firepower Management Center Cross-Site Scripting Vulnerability
Published 2019-01-23 · Modified
6.11 PoCEPSS 0.039
CVE-2019-1671
Cisco Firepower Management Center Cross-Site Scripting Vulnerability
Published 2019-02-07 · Modified
6.1EPSS 0.012
CVE-2019-1930
Cisco Firepower Management Center RSS Cross-Site Scripting Vulnerabilities
Published 2019-07-06 · Modified
6.1EPSS 0.011
CVE-2019-1931
Cisco Firepower Management Center RSS Cross-Site Scripting Vulnerabilities
Published 2019-07-06 · Modified
6.1EPSS 0.011
CVE-2024-20273
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerability
Published 2024-10-23 · Analyzed
6.1EPSS 0.004
CVE-2024-20372
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.
Published 2024-10-23 · Analyzed
6.1EPSS 0.004
CVE-2024-20386
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.
Published 2024-10-23 · Analyzed
6.1EPSS 0.004
CVE-2024-20409
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.
Published 2024-10-23 · Analyzed
6.1EPSS 0.003
CVE-2024-20410
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.
Published 2024-10-23 · Analyzed
6.1EPSS 0.003
CVE-2024-20415
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.
Published 2024-10-23 · Analyzed
6.1EPSS 0.003
CVE-2025-20235
Cisco Secure Firewall Management Center Software Cross-Site Scripting Vulnerability
Published 2025-08-14 · Analyzed
6.1EPSS 0.003
CVE-2019-1833
Cisco Firepower Threat Defense Software SSL/TLS Policy Bypass Vulnerability
Published 2019-05-16 · Modified
5.8EPSS 0.017
CVE-2018-0281
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief denial of service (DoS) condition. The vulnerability is due to the incorrect handling of a Transport Layer Security (TLS) extension during TLS connection setup for the affected software. An attacker could exploit this vulnerability by sending a crafted TLS connection setup request to an affected device. A successful exploit could allow the attacker to cause the Snort detection engine on the affected device to restart, resulting in a DoS condition. Cisco Bug IDs: CSCvg97808.
Published 2018-05-02 · Modified
5.8EPSS 0.014
CVE-2018-0283
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief denial of service (DoS) condition. The vulnerability is due to the incorrect handling of Transport Layer Security (TLS) TCP connection setup for the affected software. An attacker could exploit this vulnerability by sending crafted TLS traffic to an affected device. A successful exploit could allow the attacker to cause the Snort detection engine on the affected device to restart, resulting in a DoS condition. Cisco Bug IDs: CSCvg99327.
Published 2018-05-02 · Modified
5.8EPSS 0.014
CVE-2024-20274
Cisco Secure Firewall Management Center HTML Injection Vulnerability
Published 2024-10-23 · Analyzed
5.5EPSS 0.004
CVE-2024-20300
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerability
Published 2024-10-23 · Analyzed
5.4EPSS 0.004
CVE-2024-20269
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerability
Published 2024-10-23 · Analyzed
5.4EPSS 0.004
CVE-2024-20403
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.
Published 2024-10-23 · Analyzed
5.4EPSS 0.003
CVE-2020-3307
Cisco Firepower Management Center Arbitrary Log File Write Vulnerability
Published 2020-05-06 · Modified
5.3EPSS 0.010
CVE-2022-20941
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to missing authorization for certain resources in the web-based management interface together with insufficient entropy in these resource names. An attacker could exploit this vulnerability by sending a series of HTTPS requests to an affected device to enumerate resources on the device. A successful exploit could allow the attacker to retrieve sensitive information from the device.
Published 2022-11-10 · Modified
5.3EPSS 0.007
CVE-2024-20388
A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to determine valid user names on an affected device. This vulnerability is due to improper authentication of password update responses. An attacker could exploit this vulnerability by forcing a password reset on an affected device. A successful exploit could allow the attacker to determine valid user names in the unauthenticated response to a forced password reset.
Published 2024-10-23 · Analyzed
5.3EPSS 0.004
CVE-2020-3308
Cisco Firepower Threat Defense Software Signature Verification Bypass Vulnerability
Published 2020-05-06 · Modified
4.9EPSS 0.006
1 / 2Next →